Upgrade detection method and device

CN120457412APending Publication Date: 2025-08-08YINWANG INTELLIGENT TECHNOLOGIES CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380088828.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-03-28
Publication Date
2025-08-08

AI Technical Summary

Technical Problem

During the OTA upgrade process of smart cars, the ECU loses contact with the OTA installer, resulting in a high upgrade failure rate, making it impossible to accurately determine whether the ECU has been correctly upgraded to the latest version.

Method used

By performing additional reset operations or rollback operations after the ECU receives the message sent by the OTA installer, the communication between the ECU and the OTA installer is restored, improving the upgrade success rate and the reliability of the vehicle OTA upgrade.

Benefits of technology

It improves the success rate of ECU upgrades and the reliability of vehicle OTA upgrades, ensuring that OTA installers can accurately judge the ECU upgrade results and ensure the uniformity of software versions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120457412A_ABST
    Figure CN120457412A_ABST
Patent Text Reader

Abstract

The invention discloses an upgrade detection method and device, and the method comprises the steps that under the condition that an ECU executes a first reset operation and is disconnected with an OTA installer, the ECU can recover the communication between the ECU and the OTA installer by executing at least one second reset operation within a first time range, the first reset operation is the first reset operation executed after the ECU flashes first upgrade software, and therefore the ECU can recover the communication between the ECU and the OTA installer. In the first time range, the ECU can receive a first message sent by an OTA installer, the OTA installer can also receive feedback of the ECU to the first message, and the first message is used for requesting to obtain a version number of upgrading software currently used by the ECU. According to the method, the success rate of ECU upgrading can be increased, and the reliability of OTA upgrading of the whole vehicle can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Upgrade detection method and device Technical Field

[0001] The present application relates to the field of over-the-air technology (OTA), and in particular to an upgrade detection method and device. Background Art

[0002] OTA upgrades are crucial for smart cars, enabling the upgrade of vehicle software and / or firmware. OTA upgrades offer timely, convenient, and low-cost advantages. They also enable rapid repairs of automotive software defects and the introduction of new features, enabling iterative upgrades of vehicle functionality and improving the user experience.

[0003] The modules involved in OTA upgrades mainly include OTA installers (for example, using the unified diagnostic service UDS) and the electronic control unit ECU to be upgraded. After the ECU performs a reset based on the reset information sent by the OTA installer and starts the newly installed upgrade software, if the ECU loses connection with the OTA installer, the OTA installer cannot obtain the version number of the newly installed upgrade software of the ECU, and cannot determine whether the ECU has been correctly upgraded to the latest version, causing the OTA installer to believe that the ECU upgrade has failed, so the success rate of the ECU upgrade is low.

[0004] Summary of the Invention

[0005] This application discloses an upgrade detection method and device, which are beneficial to improving the success rate of ECU upgrades and improving the reliability of vehicle OTA upgrades.

[0006] In the first aspect, the present application provides an upgrade detection method, which includes: within a first time range, the electronic control unit ECU receives a first message sent by an over-the-air OTA installer, and in response to the first message, the ECU sends a second message to the OTA installer, wherein the first message is used to request the version number of the upgrade software currently used by the ECU; wherein, before the first time range, the ECU performs a first reset operation and the ECU loses connection with the OTA installer, and the first reset operation is the first reset operation performed by the ECU after the first upgrade software is flashed; wherein, within the first time range and before the ECU receives the first message, the ECU performs at least one second reset operation or at least one rollback operation.

[0007] Here, the first reset operation is a reset operation inherent in the traditional ECU upgrade process. That is, after the OTA installer knows that the ECU has completed the flashing of the first upgrade software, the OTA installer sends a first reset message to the ECU to instruct the ECU to perform the first reset operation.

[0008] The second reset operation is different from the first reset operation. It is performed after the first reset operation, that is, the second reset operation is a new reset operation. The second reset operation is used to re-run or restart the first upgraded software after OTA flashing. For example, flashing can refer to burning the software program to a specific address in the ECU chip memory.

[0009] The prerequisite for an ECU to perform a rollback operation is that the ECU uses a partitioned format to flash the upgrade software. For example, the ECU includes a first partition and a second partition. The first partition is used to store the first upgrade software, and the second partition is used to store the second upgrade software. The second upgrade software is the software used by the ECU before the first upgrade software is flashed. A rollback operation, also known as a fallback operation, means that the ECU switches from the first partition to the second partition to start or run the second upgrade software.

[0010] Here, a loss of connection between the ECU and the OTA installer means that the ECU and the OTA installer are unable to communicate, or at least one communication link between the ECU and the OTA installer is unable to communicate between the ECU and the OTA installer. Specifically, assuming that the ECU communicates with the OTA installer via a first communication link, if the ECU and the OTA installer lose connection, the ECU will not receive any information sent by the OTA installer to the ECU via the first communication link, and the OTA installer will not receive any information sent by the ECU to the OTA installer via the first communication link.

[0011] The OTA installer is used to perform OTA software installation, rollback, and reset operations for ECUs. For example, the OTA installer can be an ECU Master. The OTA installer can be deployed on specific components within the vehicle, such as a domain controller, to update the ECUs connected to that domain controller.

[0012] The OTA installer is deployed on the vehicle's domain controller, which includes but is not limited to: a hardware and software integrated platform for supporting intelligent driving, namely an on-board computing platform, such as a mobile data center (MDC), a hardware and software integrated platform for supporting body control and chassis control, such as a vehicle domain controller (VDC), a hardware and software integrated platform for providing on-board multimedia services (for example, at least one of a head-up display, an instrument panel display, entertainment audio and video, etc.), such as a cockpit domain controller (CDC), a central computing unit, etc., one or more.

[0013] For example, when the OTA installer uses unified diagnostic services (UDS), the OTA installer may also be called a UDS installer.

[0014] In the above method, after the ECU successfully launches the first upgrade software based on the first reset operation, if the ECU loses communication with the OTA installer, one approach is to add a second reset operation to the ECU, which helps resolve the loss of communication between the ECU and the OTA installer. By increasing the number of times the ECU performs the second reset operation, the success rate of restoring communication between the ECU and the OTA installer is improved, which also helps improve the success rate of ECU upgrades and the reliability of vehicle upgrades. In another approach, by setting the ECU to launch the old version of the software (this process can also be called the ECU performing a rollback operation), it is also helpful to restore communication between the ECU and the OTA installer. In this way, the second message fed back by the ECU can also enable the OTA installer to accurately know the ECU upgrade results. In the process of unifying the vehicle version software, it is helpful to improve the accuracy of the vehicle's decision-making, thereby improving the reliability of the vehicle upgrade.

[0015] Optionally, the first message and the second message are carried by a first communication link, and the first communication link includes an Ethernet-based diagnostic communication link and / or a diagnostic communication link based on a first in-vehicle signal bus.

[0016] For example, the first communication link can be understood as a diagnostic communication link for carrying interactive information between the ECU and the OTA installer. The first communication link can be a factory default setting or a user preset setting.

[0017] For example, when the ECU is directly connected to a domain controller integrated with an OTA installer, or when the ECU is connected to the domain controller integrated with an OTA installer via a distributed gateway and the communication connection methods between the ECU and the distributed gateway, and between the distributed gateway and the OTA installer, are the same, the first communication link is an Ethernet-based diagnostic communication link or a diagnostic communication link based on the first in-vehicle signal bus. If the ECU is connected to the domain controller integrated with an OTA installer via a distributed gateway and the communication connection methods between the ECU and the distributed gateway, and between the distributed gateway and the OTA installer, are different, the first communication link includes an Ethernet-based diagnostic communication link and a diagnostic communication link based on the first in-vehicle signal bus.

[0018] It can be seen that the first communication link can have various forms based on the connection method between the OTA installer and the ECU.

[0019] Optionally, if the ECU performs the at least one second reset operation within the first timeframe and before the ECU receives the first message, the second message includes the version number of the first upgrade software. This allows the recipient of the second message (i.e., the OTA installer) to determine that the ECU upgrade was successful, thereby increasing the success rate of the ECU upgrade.

[0020] Optionally, if the ECU performs at least one rollback operation (or launches at least one old version of software) within the first timeframe and before receiving the first message, the second message includes the version number of the second upgrade software used by the ECU before the first upgrade software was flashed. This allows the receiver of the second message (i.e., the OTA installer) to determine that the ECU upgrade failed, thereby improving the accuracy of subsequent vehicle-wide decision-making.

[0021] Optionally, a triggering condition for the ECU to perform the at least one second reset operation is:

[0022] The ECU does not receive the first message sent by the OTA installer within a first preset time period after the ECU starts the first upgrade software;

[0023] Within a second preset time period after the ECU starts the first upgrade software, the ECU does not receive a heartbeat message sent by the OTA installer;

[0024] The ECU receives first indication information, where the first indication information is used to indicate that the ECU has lost contact with the OTA installer, or is used to indicate that the ECU starts to perform the second reset operation; or

[0025] The ECU receives power-off indication information, and the power-off indication information is used by the ECU to perform the second reset operation.

[0026] Here, the heartbeat message sent by the OTA installer is used to inform the peer end (ie, ECU) that the OTA installer is alive.

[0027] Exemplarily, the power-off indication information may be included in the first indication information.

[0028] Exemplarily, the first indication information is upgrade indication information carrying an upgrade package.

[0029] For example, the present application does not limit the number of times the ECU receives the first indication information.

[0030] In one implementation, before the first time range, within a third preset time period after the ECU 1 starts the first upgrade software, the ECU 1 receives the first indication information only once, which triggers the ECU to perform at least one second reset operation.

[0031] In another implementation, within the first time range, the ECU may receive the first indication information multiple times, and the ECU performing the at least one second reset operation means that the ECU performs the second reset operation once each time it receives the first indication information. Exemplarily, the first indication information is obtained by the ECU from the OTA installer. In a specific implementation, the ECU may also obtain it from the OTA manager or the vehicle control device. Here, the OTA manager (OTA Manager) may also be referred to as the OTA manager or the OTA controller (OTA Controller).

[0032] By implementing the above implementation, by setting a trigger condition for the ECU to perform the second reset operation, the consumption of ECU computing resources and electric energy can be saved.

[0033] Accordingly, a second trigger condition may also be set for the ECU to perform the rollback operation (or start the second upgrade software). The second trigger condition may be any of the following conditions:

[0034] (1) The ECU does not receive the first message sent by the OTA installer within a first preset time period after the ECU starts the first upgrade software;

[0035] (2) within a second preset time period after the ECU starts the first upgrade software, the ECU does not receive a heartbeat message sent by the OTA installer; or

[0036] (3) The ECU receives second indication information, where the second indication information is used to indicate that the ECU has lost contact with the OTA installer, or to indicate that the ECU starts executing the rollback operation.

[0037] Optionally, the first indication information is carried via a second communication link, which is different from the first communication link.

[0038] Exemplarily, the type of the second communication link may be a diagnostic communication link or a service communication link, wherein the message carried on the diagnostic communication link may be called a diagnostic message, and the message carried on the service communication link may be called a service message.

[0039] In the event that the ECU loses connection with the OTA installer, the first indication information is carried through other redundant communication links, such as the second communication link, to ensure that the ECU receives the first indication information, thereby triggering the ECU to perform a second reset operation, which is conducive to restoring communication between the ECU and the OTA installer based on the first communication link.

[0040] Optionally, the number of times the second reset operation is performed is associated with the number of times the ECU receives the first indication information.

[0041] Here, the association may be, for example, that the number of times the second reset operation is performed is equal to the number of times the ECU receives the first indication information, and each time the ECU receives the first indication information, the ECU performs the second reset operation based on the first indication information. For example, the association may be that the number of times the second reset operation is performed is not less than the number of times the ECU receives the first indication information, that is, the ECU receives the first indication information once, and the first indication information triggers the ECU to perform the second reset operation at least once.

[0042] Optionally, the first time range is at least one first detection cycle, and the at least one second reset operation corresponds to the at least one first detection cycle.

[0043] For example, the at least one second reset operation corresponds to the at least one first detection cycle, which means that each second reset operation corresponds to a first detection cycle, that is, after each second reset operation is performed, there can be a first detection cycle to monitor whether there is a first message from the OTA installer.

[0044] By implementing the above implementation method, the ECU side can sense the detection cycle. When the ECU loses contact with the OTA installer, under the aforementioned trigger conditions, the ECU can actively start at least one second reset operation to achieve self-inspection and self-healing, which is conducive to improving the success rate of ECU upgrades.

[0045] Optionally, the method further includes: when the number of the at least one second reset operation reaches a first threshold, the ECU stops monitoring the first message on the first communication link.

[0046] By implementing the above implementation, the power consumption of the ECU during the upgrade process can be saved by limiting the number of executions of the second reset operation.

[0047] Optionally, the ECU includes a first partition and a second partition, the first partition is used to store the first upgrade software, the second partition is used to store the second upgrade software, the second upgrade software is the software used by the ECU before flashing the first upgrade software, the number of the at least one second reset operation reaches a first threshold, and the method also includes: the ECU starts the second upgrade software; within the second detection cycle, if the ECU receives the first message from the OTA installer based on the first communication link, it sends a third message to the OTA installer based on the first communication link; wherein, the third message includes the version number of the second upgrade software.

[0048] Exemplarily, the process in which the ECU switches from the first partition to the second partition and starts the second upgraded software may also be referred to as the process in which the ECU performs a rollback operation.

[0049] In the above implementation, when the ECU uses a partitioned form to flash the upgrade software, the problem of loss of connection between the ECU and the OTA installer can also be solved by first executing the second reset operation and then executing the rollback operation. That is, when the number of times the ECU executes the second reset operation reaches the first threshold but the communication between the ECU and the OTA installer based on the first communication link is still not restored, the ECU can also execute the rollback operation to try to restore the communication between the ECU and the OTA installer. In this way, the third message fed back by the ECU after executing the rollback operation can enable the OTA installer to accurately know the upgrade result of the ECU, which is beneficial to improving the reliability of the vehicle upgrade.

[0050] Optionally, before the ECU starts the second upgrade software, the method also includes: the ECU receives rollback information sent by the OTA installer, the rollback information is carried by a second communication link, and the second communication link is different from the first communication link; the ECU starts the second upgrade software, including: the ECU starts the second upgrade software based on the rollback information.

[0051] As a possible implementation manner, the above process of starting the second upgrade software may also be referred to as performing a rollback operation, that is, the ECU performing the rollback operation, including: the ECU performing the rollback operation based on the rollback information.

[0052] When implementing the above-mentioned implementation method, the problem of loss of connection between the ECU and the OTA installer is solved by first performing a second reset operation and then performing a rollback operation. The rollback operation performed by the ECU after the second reset operation can be based on the rollback information sent by the OTA installer through a redundant communication link (such as the second communication link), which is beneficial to improving the reliability of the vehicle upgrade.

[0053] Optionally, the ECU is communicatively connected to the OTA installer via a distributed gateway in the vehicle, the first communication link includes a diagnostic communication link based on Ethernet and a diagnostic communication link based on a first in-vehicle signal bus, and the second communication link includes:

[0054] At least one of a service communication link based on a second in-vehicle signal bus and a service communication link based on Ethernet; or

[0055] a third communication link and a fourth communication link, the third communication link being used to connect the OTA installer with the distributed gateway, and the fourth communication link being used to connect the distributed gateway with the ECU;

[0056] Wherein, if the Ethernet-based diagnostic communication link in the first communication link is used to connect the OTA installer and the distributed gateway, and the diagnostic communication link based on the first in-vehicle signal bus in the first communication link is used to connect the distributed gateway and the ECU,

[0057] When the third communication link is a diagnostic communication link based on any in-vehicle signal bus, the fourth communication link is a diagnostic communication link based on Ethernet or a diagnostic communication link based on a third in-vehicle signal bus, and the third in-vehicle signal bus is different from the first in-vehicle signal bus; or

[0058] When the third communication link is a service communication link based on Ethernet or any in-vehicle signal bus, the fourth communication link is a service communication link based on Ethernet or any in-vehicle signal bus.

[0059] Exemplarily, the distributed gateway may also be referred to as a vehicle integrated unit (VIU) or a virtual gateway (VGW).

[0060] The implementation described above provides various forms of the first communication link and the second communication link under the architecture where the ECU communicates with the OTA installer via a distributed gateway, satisfying the application of the upgrade detection method in various scenarios.

[0061] Optionally, the first communication link is an Ethernet-based diagnostic communication link, and the second communication link includes: at least one of a business communication link based on a second in-vehicle signal bus and a business communication link based on Ethernet; or, a diagnostic communication link based on a second in-vehicle signal bus.

[0062] Optionally, the first communication link is a diagnostic communication link based on a first in-vehicle signal bus, and the second communication link includes: at least one of a business communication link based on a second in-vehicle signal bus and a business communication link based on Ethernet; or, at least one of a diagnostic communication link based on a third in-vehicle signal bus and a diagnostic communication link based on Ethernet, and the third in-vehicle signal bus is different from the first in-vehicle signal bus.

[0063] The second in-vehicle signal bus may be the same as or different from the first in-vehicle signal bus.

[0064] In the above implementation, the examples of the first communication link and the second communication link are applicable not only to the scenario where the ECU communicates directly with the OTA installer, but also to the scenario where the ECU communicates with the OTA installer through a distributed gateway.

[0065] In second aspect, the present application provides an upgrade detection method, which includes: within a first time range, an over-the-air OTA installer performs a first operation, and the first operation is used to restore communication between the OTA installer and an electronic control unit ECU, and the ECU is an electronic control unit connected to the OTA installer; wherein, before the first time range, the OTA installer sends a first reset message and does not receive a response from the ECU to the first message, and the first reset message is used to request the ECU to perform a first reset operation, and the first reset operation is the first reset operation performed by the ECU after the first upgrade software is flashed, and the first message is used to request the version number of the upgrade software currently used by the ECU; within the first time range, if the ECU and the OTA installer restore communication, the OTA installer receives a second message from the ECU in response to the first message.

[0066] Here, the first reset operation can refer to the description of the corresponding content in the above first aspect.

[0067] Exemplarily, the reasons why the OTA installer did not receive the ECU's response to the first message before the first time range include: the ECU did not receive the first message sent by the OTA installer due to loss of connection, and therefore would not send a response to the first message to the OTA installer, so the OTA installer did not receive the ECU's response to the first message; or, the ECU first received the first message sent by the OTA installer and sent a response to the first message to the OTA installer, but because the ECU lost connection, the OTA installer did not receive the ECU's response to the first message.

[0068] For example, before the first time range, when the OTA installer sends the first reset information and does not receive a response to the first message from the ECU, the OTA installer may also determine that the ECU has lost contact with the OTA installer.

[0069] In the above method, when the OTA installer sends a first reset message and does not receive a response from the ECU to the first message, the OTA installer attempts to communicate between the lost ECU and the OTA installer by performing a first operation within a first time range, and monitors whether there is a second message from the ECU in response to the first message within the first time range. In this way, the OTA installer can accurately determine whether the ECU has been upgraded to the correct version through the second message. In the process of unifying the vehicle version software, it is beneficial to improve the accuracy of the vehicle decision-making, thereby improving the reliability of the vehicle upgrade.

[0070] Optionally, the first operation includes: repeatedly sending the first message.

[0071] Exemplarily, repeated transmission may be understood as: repeatedly transmitting the first message at equal intervals, or transmitting the first message at increasing intervals, or transmitting the first message at decreasing intervals.

[0072] It can be understood that before the first time range, the OTA installer did not receive feedback from the ECU on the first message, so the OTA installer could not know whether the ECU received the first message. In this case, within the first time range, when the OTA installer performs the operation of "repeatedly sending the first message", once the communication between the ECU and the OTA installer is restored, the ECU can receive the first message, and the OTA installer can also receive the second message from the ECU in response to the first message, so that the OTA installer can know that the communication between the ECU and the OTA installer has been restored, which is conducive to improving the success rate of the ECU upgrade and the reliability of the vehicle upgrade.

[0073] Optionally, the first message and the second message are carried by a first communication link, wherein the first communication link includes an Ethernet-based diagnostic communication link and / or a diagnostic communication link based on a first in-vehicle signal bus. The first communication link can be described in the corresponding content of the first aspect and is not repeated here.

[0074] Optionally, the ECU includes a first partition and a second partition, the first partition is used to store the first upgrade software, and the second partition is used to store the second upgrade software, the second upgrade software is the software used by the ECU before flashing the first upgrade software, and the first operation also includes: sending rollback information at least once based on a second communication link, the rollback information is used to instruct the ECU to start the second upgrade software, and the second communication link is different from the first communication link.

[0075] Exemplarily, the process of the ECU starting the second upgrade software may also be referred to as the ECU performing a rollback operation, that is, the rollback information may also be understood as being used to instruct the ECU to perform the rollback operation.

[0076] Exemplarily, the type of the second communication link is a diagnostic communication link or a service communication link. When the type of the second communication link is a diagnostic communication link, the message carried on the second communication link can be called a diagnostic message; and when the type of the second communication link is a service communication link, the message carried on the second communication link can be called a service message.

[0077] By implementing the above implementation method, the OTA installer directly adopts a rollback strategy to solve the ECU loss of connection problem, that is, based on a redundant communication link other than the first communication link, such as the second communication link, the rollback information is sent at least once. In this way, it can be ensured that the ECU can receive the rollback information, which is conducive to improving the success rate of restoring communication between the ECU and the OTA installer based on the first communication link.

[0078] Optionally, the first operation also includes: sending a first indication message at least once based on a second communication link, the first indication message being used to indicate that the ECU has lost connection with the OTA installer, or being used to instruct the ECU to perform a second reset operation, the second communication link being different from the first communication link; or, sending a heartbeat message based on the first communication link.

[0079] Here, the second reset operation is different from the first reset operation described above. The second reset operation is a reset operation performed after the first reset operation, that is, the second reset operation is an additional reset operation. The second reset operation is used to re-run or start the first upgrade software after OTA flashing.

[0080] For example, the heartbeat message is used to indicate that the OTA installer is online or alive, and whether the ECU receives the heartbeat message can serve as a trigger condition for the ECU to determine whether to perform at least one second reset operation or at least one rollback operation.

[0081] By implementing the above-mentioned implementation method, the OTA installer can actively send a first indication information or a heartbeat message based on a redundant communication link other than the first communication link, such as a second communication link, to trigger the ECU to perform at least one second reset operation, which is conducive to solving the ECU loss of connection problem and improving the success rate of ECU upgrades.

[0082] Optionally, the number of times the second reset operation is performed is associated with the number of times the first indication information is sent.

[0083] Exemplarily, the association can be understood as: the number of executions of the second reset operation is equal to the number of transmissions of the first indication information, and each time the OTA installer sends the first indication information, the corresponding ECU performs the second reset operation based on the first indication information.

[0084] Exemplarily, the association may be understood as follows: the number of executions of the second reset operation is greater than the number of transmissions of the first indication information. For example, the OTA installer transmits the first indication information once, triggering the ECU to execute multiple second reset operations.

[0085] Optionally, the ECU includes a first partition and a second partition, the first partition is used to store the first upgrade software, and the second partition is used to store the second upgrade software, the second upgrade software is the software used by the ECU before flashing the first upgrade software, and the first operation also includes: when the number of times the first indication information is sent reaches a first threshold and communication between the ECU and the OTA installer has not been restored, the OTA installer sends a rollback message to the ECU based on a second communication link, and the rollback message is used to instruct the ECU to start the second upgrade software, and the second communication link is different from the first communication link.

[0086] Exemplarily, after the number of times the first indication information is sent reaches a first threshold, the number of times the rollback information is sent is less than or equal to a second threshold.

[0087] By implementing the above implementation method, if the ECU has a partition storing an old version of software, the OTA installer can use a reset-first-then-rollback strategy to resolve the ECU's loss of connection problem. That is, if the OTA installer sends the first indication message a number of times that reaches a first threshold but the ECU's loss of connection problem is still not resolved, a rollback message can be sent to the ECU through a redundant communication link. In this way, the success rate of restoring communication between the ECU and the OTA installer based on the first communication link can be improved.

[0088] Optionally, after the OTA installer receives the second message, the method further includes: determining an upgrade result of the ECU according to the second message.

[0089] Furthermore, the upgrade result of the ECU is determined based on the second message, including: the version number included in the second message is the same as the version number of the first upgrade software, and the OTA installer determines that the ECU upgrade is successful; or, the version number included in the second message is different from the version number of the first upgrade software, and the OTA installer determines that the ECU upgrade has failed.

[0090] By implementing the above implementation method, the OTA installer can determine the upgrade result of the ECU based on the second message. According to this method, the OTA installer can summarize the upgrade results of each ECU, and when unifying the software version used by the entire vehicle, it can accurately decide whether a certain ECU should be upgraded or rolled back. For example, during a certain vehicle upgrade, ECU1 upgraded successfully, and ECU2 failed to upgrade (that is, the rollback was successful). In this case, in order to ensure the uniformity of the software version, ECU2 can be instructed to upgrade again or ECU1 can be instructed to roll back (that is, start the old version of the software, such as the second version of the software). In this way, the business can be realized. Normal operation in a working environment with matching software versions, which is conducive to improving the reliability of vehicle upgrades.

[0091] Optionally, after determining that the ECU upgrade has failed, the method further includes: sending upgrade indication information to the ECU, where the upgrade indication information is used to instruct the ECU to re-execute the OTA upgrade based on the first upgrade software.

[0092] By implementing the above implementation, when the communication between the ECU and the OTA installer has been restored, the OTA installer sends upgrade instruction information to the ECU, which can improve the success rate of the ECU upgrade.

[0093] Optionally, within the first time range, if the OTA installer does not receive the second message, the method further includes: the OTA installer sending feedback information to the OTA manager, where the feedback information is used to indicate that the ECU has lost contact with the OTA installer.

[0094] By implementing the above implementation method, the OTA installer can also send feedback information to the OTA manager to inform him of the ECU loss of connection, so that the OTA manager can try to solve the ECU loss problem from the perspective of the entire vehicle, such as vehicle inspection, which is conducive to improving the success rate of ECU upgrades and the reliability of vehicle upgrades.

[0095] The beneficial effects of the following technical features can refer to the description of the beneficial effects of the same technical features in the first aspect, and will not be repeated here.

[0096] Optionally, the ECU is communicatively connected to the OTA installer via a distributed gateway in the vehicle, the first communication link includes a diagnostic communication link based on Ethernet and a diagnostic communication link based on a first in-vehicle signal bus, and the second communication link includes:

[0097] At least one of a service communication link based on a second in-vehicle signal bus and a service communication link based on Ethernet; or

[0098] a third communication link and a fourth communication link, the third communication link being used to connect the OTA installer with the distributed gateway, and the fourth communication link being used to connect the distributed gateway with the ECU;

[0099] Wherein, if the Ethernet-based diagnostic communication link in the first communication link is used to connect the OTA installer and the distributed gateway, and the diagnostic communication link based on the first in-vehicle signal bus in the first communication link is used to connect the distributed gateway and the ECU,

[0100] When the third communication link is a diagnostic communication link based on any in-vehicle signal bus, the fourth communication link is a diagnostic communication link based on Ethernet or a diagnostic communication link based on a third in-vehicle signal bus, and the third in-vehicle signal bus is different from the first in-vehicle signal bus; or

[0101] When the third communication link is a service communication link based on Ethernet or any in-vehicle signal bus, the fourth communication link is a service communication link based on Ethernet or any in-vehicle signal bus.

[0102] Optionally, the first communication link is an Ethernet-based diagnostic communication link, and the second communication link includes: at least one of a business communication link based on a second in-vehicle signal bus and a business communication link based on Ethernet; or, a diagnostic communication link based on a second in-vehicle signal bus.

[0103] Optionally, the first communication link is a diagnostic communication link based on a first in-vehicle signal bus, and the second communication link includes: at least one of a business communication link based on a second in-vehicle signal bus and a business communication link based on Ethernet; or, at least one of a diagnostic communication link based on a third in-vehicle signal bus and a diagnostic communication link based on Ethernet, and the third in-vehicle signal bus is different from the first in-vehicle signal bus.

[0104] In the third aspect, the present application provides an upgrade detection method, which includes: the over-the-air OTA manager receives feedback information sent by the OTA installer, and the feedback information is used to indicate that the electronic control unit ECU has lost contact with the OTA installer; the OTA manager sends a power-off indication information, and the power-off indication information is used for the ECU to perform a second reset operation, and the second reset operation is a reset operation after the ECU performs the first reset operation, and the first reset operation is the first reset operation performed by the ECU after the first upgrade software is flashed.

[0105] Here, the OTA manager (OTA Manager) can also be called an OTA manager or an OTA controller (OTA Controller). For example, the OTA manager is mainly used to connect to cloud devices to achieve vehicle management.

[0106] Here, the OTA installer can be understood as the executor or execution unit of the OTA manager. For example, the OTA installer can be the ECU Master. The OTA installer is used to perform OTA software installation, rollback, and reset operations for ECUs. The OTA installer can be deployed on specific components within the vehicle, such as the domain controller, to update the ECUs connected to the domain controller.

[0107] For example, when the OTA installer uses unified diagnostic services (UDS), the OTA installer may also be called a UDS installer.

[0108] The OTA manager and OTA installer can be deployed on the same domain controller or on different domain controllers within the vehicle. The OTA manager and OTA installer can exist independently, or the OTA installer can be integrated into the OTA manager, without specific limitations.

[0109] In the above method, in response to the feedback information sent by the OTA installer, the OTA manager controls the entire vehicle to power off and sleep for a period of time and then power on again by sending a power-off indication message. In this way, the ECU performs an additional second reset operation after performing the first reset operation to retry starting or running the new version of the upgrade software. This attempts to solve the ECU loss of connection problem from the perspective of the entire vehicle, which is beneficial to improving the success rate of restoring communication between the ECU and the OTA installer, and can also be beneficial to the reliability of the entire vehicle upgrade.

[0110] Optionally, after the OTA manager sends the power-off indication information, the method also includes: within a preset time period, the OTA manager receives the result information sent by the OTA installer, the result information is used to indicate the upgrade result of the ECU, and the result information is a response to the result query information sent by the OTA manager; the OTA manager obtains the upgrade result of the ECU based on the result information.

[0111] By implementing the above implementation method, the OTA manager can know the upgrade results of the ECU based on the result information. According to this method, the OTA manager can accurately know the upgrade results of each ECU in the vehicle. When unifying the software version used in the entire vehicle, it can accurately decide whether a certain ECU should be upgraded or rolled back. For example, during a vehicle upgrade, ECU1 is successfully upgraded and ECU2 fails to upgrade (that is, the rollback is successful). In this case, in order to ensure the uniformity of the software version, ECU2 can be instructed to upgrade again or ECU1 can be instructed to roll back. In this way, the business can be realized to operate normally in a working environment with matching software versions.

[0112] Optionally, the method further includes: if the OTA manager does not receive the result information within the preset time period, the OTA manager prompts the vehicle user that the ECU has lost contact with the OTA installer and requests manual processing.

[0113] For example, the user of the vehicle may be one or more of the driver of the vehicle, the user of the vehicle, the owner of the vehicle, a person riding in the vehicle, and the like.

[0114] By implementing the above implementation method, if the OTA manager still fails to resolve the ECU loss of connection by powering on and off the vehicle, he or she can also request manual processing from the vehicle user.

[0115] In a fourth aspect, the present application provides an upgrade detection device, which is an electronic control unit ECU or is included in the ECU, and the device includes: a receiving unit, a processing unit and a sending unit, wherein within a first time range, the receiving unit receives a first message sent by an over-the-air OTA installer, and in response to the first message, the sending unit is used to send a second message to the OTA installer, and the first message is used to request to obtain the version number of the upgrade software currently used by the ECU; wherein before the first time range, the processing unit performed a first reset operation and the ECU lost contact with the OTA installer, and the first reset operation was the first reset operation performed by the processing unit after flashing the first upgrade software; wherein, within the first time range and before the receiving unit received the first message, the processing unit performed at least one second reset operation or at least one rollback operation.

[0116] Optionally, the first message and the second message are carried by a first communication link, and the first communication link includes an Ethernet-based diagnostic communication link and / or a diagnostic communication link based on a first in-vehicle signal bus.

[0117] Optionally, when the ECU performs the at least one second reset operation within the first time range and before the ECU receives the first message, the second message includes the version number of the first upgrade software.

[0118] Optionally, within the first time range and before the ECU receives the first message, if the ECU performs at least one rollback operation, the second message includes the version number of the second upgrade software, and the second upgrade software is the software used by the ECU before flashing the first upgrade software.

[0119] Optionally, a triggering condition for the ECU to perform the at least one second reset operation is:

[0120] The ECU does not receive the first message sent by the OTA installer within a first preset time period after the ECU starts the first upgrade software;

[0121] Within a second preset time period after the ECU starts the first upgrade software, the ECU does not receive a heartbeat message sent by the OTA installer;

[0122] The ECU receives first indication information, where the first indication information is used to indicate that the ECU has lost contact with the OTA installer, or is used to indicate that the ECU starts to perform the second reset operation; or

[0123] The ECU receives power-off indication information, and the power-off indication information is used by the ECU to perform the second reset operation.

[0124] Exemplarily, the triggering condition for the ECU to perform the at least one rollback operation is:

[0125] (1) The ECU does not receive the first message sent by the OTA installer within a first preset time period after the ECU starts the first upgrade software;

[0126] (2) within a second preset time period after the ECU starts the first upgrade software, the ECU does not receive a heartbeat message sent by the OTA installer; or

[0127] (3) The ECU receives second indication information, where the second indication information is used to indicate that the ECU has lost contact with the OTA installer, or to indicate that the ECU starts executing the rollback operation.

[0128] Optionally, the first indication information is carried via a second communication link, which is different from the first communication link.

[0129] Optionally, the number of times the second reset operation is performed is associated with the number of times the ECU receives the first indication information.

[0130] Optionally, the first time range is at least one first detection cycle, and the at least one second reset operation corresponds to the at least one first detection cycle.

[0131] Optionally, the processing unit is further configured to: when the number of the at least one second reset operation reaches a first threshold, stop monitoring the first message on the first communication link.

[0132] Optionally, the ECU includes a first partition and a second partition, the first partition is used to store the first upgrade software, the second partition is used to store the second upgrade software, the second upgrade software is the software used by the ECU before the first upgrade software is flashed, and the number of at least one second reset operation reaches a first threshold: the processing unit is also used to start the second upgrade software; within the second detection cycle, if the receiving unit receives the first message from the OTA installer based on the first communication link, the sending unit is also used to send a third message to the OTA installer based on the first communication link; wherein, the third message includes the version number of the second upgrade software.

[0133] Optionally, the receiving unit is further used to receive rollback information sent by the OTA installer, where the rollback information is carried by a second communication link, which is different from the first communication link; the processing unit is specifically used to: start the second upgrade software based on the rollback information.

[0134] Optionally, the ECU is communicatively connected to the OTA installer via a distributed gateway in the vehicle, the first communication link includes a diagnostic communication link based on Ethernet and a diagnostic communication link based on a first in-vehicle signal bus, and the second communication link includes:

[0135] At least one of a service communication link based on a second in-vehicle signal bus and a service communication link based on Ethernet; or

[0136] a third communication link and a fourth communication link, the third communication link being used to connect the OTA installer with the distributed gateway, and the fourth communication link being used to connect the distributed gateway with the ECU;

[0137] Wherein, if the Ethernet-based diagnostic communication link in the first communication link is used to connect the OTA installer and the distributed gateway, and the diagnostic communication link based on the first in-vehicle signal bus in the first communication link is used to connect the distributed gateway and the ECU,

[0138] When the third communication link is a diagnostic communication link based on any in-vehicle signal bus, the fourth communication link is a diagnostic communication link based on Ethernet or a diagnostic communication link based on a third in-vehicle signal bus, and the third in-vehicle signal bus is different from the first in-vehicle signal bus; or

[0139] When the third communication link is a service communication link based on Ethernet or any in-vehicle signal bus, the fourth communication link is a service communication link based on Ethernet or any in-vehicle signal bus.

[0140] Optionally, the first communication link is an Ethernet-based diagnostic communication link, and the second communication link includes: at least one of a business communication link based on a second in-vehicle signal bus and a business communication link based on Ethernet; or, a diagnostic communication link based on a second in-vehicle signal bus.

[0141] Optionally, the first communication link is a diagnostic communication link based on a first in-vehicle signal bus, and the second communication link includes: at least one of a business communication link based on a second in-vehicle signal bus and a business communication link based on Ethernet; or, at least one of a diagnostic communication link based on a third in-vehicle signal bus and a diagnostic communication link based on Ethernet, and the third in-vehicle signal bus is different from the first in-vehicle signal bus.

[0142] In the fifth aspect, the present application provides an upgrade detection device, which is an over-the-air OTA installer or is included in the OTA installer, and the device includes: a sending unit and a receiving unit, wherein, within a first time range, the sending unit is used to perform a first operation, and the first operation is used to restore communication between the OTA installer and the electronic control unit ECU, and the ECU is an electronic control unit connected to the OTA installer; wherein, before the first time range, the sending unit is used to send a first reset information and the receiving unit does not receive a response from the ECU to the first message, and the first reset information is used to request the ECU to perform a first reset operation, and the first reset operation is the first reset operation performed by the ECU after the first upgrade software is flashed, and the first message is used to request to obtain the version number of the upgrade software currently used by the ECU; within the first time range, if the ECU and the OTA installer resume communication, the receiving unit receives a second message from the ECU in response to the first message.

[0143] Optionally, the first operation includes: repeatedly sending the first message.

[0144] Optionally, the first message and the second message are carried by a first communication link, and the first communication link includes an Ethernet-based diagnostic communication link and / or a diagnostic communication link based on a first in-vehicle signal bus.

[0145] Optionally, the ECU includes a first partition and a second partition, the first partition is used to store the first upgrade software, and the second partition is used to store the second upgrade software, the second upgrade software is the software used by the ECU before flashing the first upgrade software, and the first operation also includes: sending rollback information at least once based on a second communication link, the rollback information is used to instruct the ECU to start the second upgrade software, and the second communication link is different from the first communication link.

[0146] Optionally, the first operation also includes: sending a first indication message at least once based on a second communication link, the first indication message being used to indicate that the ECU has lost connection with the OTA installer, or being used to instruct the ECU to perform a second reset operation, the second communication link being different from the first communication link; or, sending a heartbeat message based on the first communication link.

[0147] Optionally, the number of times the second reset operation is performed is associated with the number of times the first indication information is sent.

[0148] Optionally, the ECU includes a first partition and a second partition, the first partition is used to store the first upgrade software, and the second partition is used to store the second upgrade software, the second upgrade software is the software used by the ECU before flashing the first upgrade software, and the first operation also includes: when the number of times the first indication information is sent reaches a first threshold and communication between the ECU and the OTA installer has not been restored, the OTA installer sends a rollback message to the ECU based on a second communication link, and the rollback message is used to instruct the ECU to start the second upgrade software, and the second communication link is different from the first communication link.

[0149] Optionally, after the OTA installer receives the second message, the device further includes a processing unit, and the processing unit is used to determine the upgrade result of the ECU according to the second message.

[0150] Furthermore, the processing unit is specifically used to: the version number included in the second message is the same as the version number of the first upgrade software, and the OTA installer determines that the ECU upgrade is successful; or, the version number included in the second message is different from the version number of the first upgrade software, and the OTA installer determines that the ECU upgrade has failed.

[0151] Optionally, after the processing unit determines that the ECU upgrade has failed, the sending unit is further used to: send upgrade indication information to the ECU, where the upgrade indication information is used to instruct the ECU to re-perform OTA upgrade based on the first upgrade software.

[0152] Optionally, within the first time range, if the receiving unit does not receive the second message, the sending unit is further used to: send feedback information to the OTA manager, where the feedback information is used to indicate that the ECU has lost contact with the OTA installer.

[0153] Optionally, the ECU is communicatively connected to the OTA installer via a distributed gateway in the vehicle, the first communication link includes a diagnostic communication link based on Ethernet and a diagnostic communication link based on a first in-vehicle signal bus, and the second communication link includes:

[0154] At least one of a service communication link based on a second in-vehicle signal bus and a service communication link based on Ethernet; or

[0155] a third communication link and a fourth communication link, the third communication link being used to connect the OTA installer with the distributed gateway, and the fourth communication link being used to connect the distributed gateway with the ECU;

[0156] Wherein, if the Ethernet-based diagnostic communication link in the first communication link is used to connect the OTA installer and the distributed gateway, and the diagnostic communication link based on the first in-vehicle signal bus in the first communication link is used to connect the distributed gateway and the ECU,

[0157] When the third communication link is a diagnostic communication link based on any in-vehicle signal bus, the fourth communication link is a diagnostic communication link based on Ethernet or a diagnostic communication link based on a third in-vehicle signal bus, and the third in-vehicle signal bus is different from the first in-vehicle signal bus; or

[0158] When the third communication link is a service communication link based on Ethernet or any in-vehicle signal bus, the fourth communication link is a service communication link based on Ethernet or any in-vehicle signal bus.

[0159] Optionally, the first communication link is an Ethernet-based diagnostic communication link, and the second communication link includes: at least one of a business communication link based on a second in-vehicle signal bus and a business communication link based on Ethernet; or, a diagnostic communication link based on a second in-vehicle signal bus.

[0160] Optionally, the first communication link is a diagnostic communication link based on a first in-vehicle signal bus, and the second communication link includes: at least one of a business communication link based on a second in-vehicle signal bus and a business communication link based on Ethernet; or, at least one of a diagnostic communication link based on a third in-vehicle signal bus and a diagnostic communication link based on Ethernet, and the third in-vehicle signal bus is different from the first in-vehicle signal bus.

[0161] In the sixth aspect, the present application provides an upgrade detection device, which is an over-the-air OTA manager or is included in the OTA manager, and the device includes: a receiving unit and a sending unit, wherein the receiving unit receives feedback information sent by the OTA installer, and the feedback information is used to indicate that the electronic control unit ECU has lost contact with the OTA installer; the sending unit is used to send power-off indication information, and the power-off indication information is used for the ECU to perform a second reset operation, and the second reset operation is a reset operation after the ECU performs the first reset operation, and the first reset operation is the first reset operation performed by the ECU after flashing the first upgrade software.

[0162] Optionally, within a preset time period after the sending unit sends the power-off indication information, the receiving unit receives result information sent by the OTA installer, and the result information is used to indicate the upgrade result of the ECU, and the result information is a response to the result query information sent by the sending unit; the device also includes a processing unit, and the processing unit is used to: obtain the upgrade result of the ECU based on the result information.

[0163] Optionally, if the receiving unit does not receive the result information within the preset time period, the processing unit is further configured to prompt the vehicle user that the ECU has lost contact with the OTA installer and request manual processing.

[0164] In a seventh aspect, the present application provides a chip comprising at least one processor and a communication interface, wherein the communication interface is configured to provide information input and / or output to the at least one processor. The chip is configured to implement the method of the first aspect or any possible implementation of the first aspect, or the chip is configured to implement the method of the second aspect or any possible implementation of the second aspect, or the chip is configured to implement the method of the third aspect or any possible implementation of the third aspect.

[0165] In an eighth aspect, the present application provides an electronic control unit, which is used to implement the method in the above-mentioned first aspect or any possible implementation of the first aspect.

[0166] Furthermore, the electronic control unit may be a device according to the fourth aspect or any possible implementation of the fourth aspect, or may be a chip according to the seventh aspect.

[0167] In the ninth aspect, the present application provides an upgrade detection system, which includes a first device and a second device, or includes a first device, a second device and a third device, wherein the first device is used to implement the method in the first aspect or any possible implementation of the first aspect, the second device is used to implement the method in the second aspect or any possible implementation of the second aspect, and the third device is used to implement the method in the third aspect or any possible implementation of the third aspect.

[0168] In the tenth aspect, the present application provides a vehicle comprising the device as described in at least one of the fourth, fifth and sixth aspects above, or comprising the chip of the seventh aspect above, or comprising the electronic control unit of the eighth aspect, or comprising the upgrade detection system of the ninth aspect.

[0169] In the eleventh aspect, the present application provides a computer-readable storage medium comprising computer instructions, which, when executed by a processor, implement the method of the first aspect or any possible implementation of the first aspect, or implement the method of the second aspect or any possible implementation of the second aspect, or implement the method of the third aspect or any possible implementation of the third aspect.

[0170] In the twelfth aspect, the present application provides a computer program product, which, when executed by a processor, implements the method in the above-mentioned first aspect or any possible embodiment of the first aspect, or implements the method in the above-mentioned second aspect or any possible implementation of the second aspect, or implements the method in the above-mentioned third aspect or any possible implementation of the third aspect.

[0171] Exemplarily, the computer program product is a software installation package. BRIEF DESCRIPTION OF THE DRAWINGS

[0172] FIG1 is a schematic diagram of the architecture of an upgrade detection system provided in an embodiment of the present application;

[0173] FIG2 is a flow chart of an upgrade detection method provided in an embodiment of the present application;

[0174] FIG3 is a flow chart of another upgrade detection method provided in an embodiment of the present application;

[0175] FIG4 is a flowchart of another upgrade detection method provided in an embodiment of the present application;

[0176] FIG5 is a flowchart of another upgrade detection method provided in an embodiment of the present application;

[0177] FIG6 is a schematic structural diagram of an upgrade detection device provided in an embodiment of the present application;

[0178] FIG7 is a schematic structural diagram of another upgrade detection device provided in an embodiment of the present application;

[0179] FIG8 is a schematic structural diagram of another upgrade detection device provided in an embodiment of the present application;

[0180] FIG9 is a schematic structural diagram of a communication device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0181] It should be noted that the prefixes such as "first" and "second" used in this application are only for distinguishing different description objects, and do not have any limiting effect on the position, order, priority, quantity or content of the described objects. For example, if the described object is a "field", then the ordinal number before the "field" in the "first field" and the "second field" does not limit the position or order between the "fields", and "first" and "second" do not limit whether the "fields" they modify are in the same message, nor do they limit the order of the "first field" and the "second field". For another example, if the described object is a "level", then the ordinal number before the "level" in the "first level" and the "second level" does not limit the priority between the "levels". For another example, the number of described objects is not limited by the prefix and can be one or more. Taking "first device" as an example, the number of "devices" can be one or more. In addition, the objects modified by different prefixes can be the same or different. For example, if the described object is a "device," then the "first device" and the "second device" can be the same device, the same type of device, or different types of devices. For another example, if the described object is "information," then the "first information" and the "second information" can be information of the same content or information of different contents. In short, the use of prefixes to distinguish the described objects in the embodiments of this application does not constitute a limitation on the described objects. For the description of the described objects, please refer to the description in the context of the claims or embodiments, and the use of such prefixes should not constitute an unnecessary limitation.

[0182] It should be noted that the descriptions used in the embodiments of the present application, such as "at least one of a1, a2, ..., and an" and the like, include any one of a1, a2, ..., and an existing alone, and any combination of any multiple of a1, a2, ..., and an, each of which can exist alone. For example, the description "at least one of a, b, and c" includes a alone, b alone, c alone, a combination of a and b, a combination of a and c, a combination of b and c, or a combination of ab and c.

[0183] To facilitate understanding, the following first introduces relevant terms that may be involved in the embodiments of this application.

[0184] (1) Ethernet-based diagnostic communication DOIP

[0185] Diagnostic communication over internet protocol (DOIP) is an Ethernet-based communication protocol used to transmit data from the Unified Diagnostic Services (UDS) protocol. DOIP is widely used in the automotive sector due to its high throughput, fast response time, and ability to perform remote diagnostics via Ethernet. For example, DOIP can be used to flash electronic control units (ECUs) during over-the-air (OTA) upgrades.

[0186] (2) Rollback operation

[0187] OTA software flashing solutions mainly include partitioning and non-partitioning methods.

[0188] The partitioning method refers to flashing the upgrade software in the A / B partition format, that is, two areas are divided in the memory, called area A and area B. Among them, one area is used to store the new version upgrade software, and the other area is used to store the old version upgrade software.

[0189] Assuming that area A stores an old version of software and the ECU currently obtains a new version of software, the ECU will flash the new version of software to area B. After the flash is complete, the ECU switches to area B to start the new version of software. If the new version of software fails, the ECU can perform a rollback operation and return to area A to start the old version of software, thus ensuring the normal use of the ECU.

[0190] The non-partitioning method means that before the ECU can flash a new version of the software, it must first enter the bootloader program to erase the current old version of the software. Understandably, in this method, if the new version of the software fails, the ECU cannot perform a rollback operation because the old version of the software has been erased.

[0191] (3)ECU upgrade process

[0192] When performing OTA upgrades in the automotive field, the flashing specifications defined by the unified diagnostic service (UDS) are generally used to complete the flashing of the ECU-side upgrade software. For example, the specific process is as follows:

[0193] Step 1: Pre-programming stage, ECU is prepared for programming;

[0194] Step 2: During the programming phase, the ECU flashes the upgrade software sent by the OTA installer (for example, using UDS). After the flash is completed, an integrity check is performed;

[0195] Step 3: Post-pre-programming phase, the ECU performs a reset operation based on the reset information sent by the OTA installer and starts the newly installed upgrade software;

[0196] Step 4: The OTA installer obtains the version number of the currently used upgrade software from the ECU. If it is the version number of the newly installed upgrade software, it is determined that the ECU has completed the entire upgrade process, and the ECU upgrade is successful.

[0197] It is understandable that in Step 4, if the ECU loses connection with the OTA installer, the OTA installer cannot obtain the version number of the newly installed upgrade software from the ECU, and cannot determine whether the ECU software is running normally, and the ECU upgrade is considered to have failed.

[0198] The technical solution in this application will be described below with reference to the accompanying drawings.

[0199] See Figure 1, which is an architectural diagram of an upgrade detection system provided in an embodiment of the present application. As shown in Figure 1, the system is deployed on a vehicle and includes an OTA manager, an OTA installer, a distributed gateway, and an electronic control unit (ECU). The OTA manager and OTA installer can also be referred to as an upgrade control system.

[0200] Here, the OTA manager (OTA Manager) can also be called an OTA manager or an OTA controller (OTA Controller). For example, the OTA manager is mainly used to connect to cloud devices to achieve vehicle management.

[0201] Here, the OTA installer can be understood as the executor or execution unit of the OTA manager. For example, the OTA installer can be the ECU Master. The OTA installer is used to perform OTA software installation, rollback, and reset operations for ECUs. The OTA installer can be deployed on specific components within the vehicle, such as the domain controller, to update the ECUs connected to the domain controller.

[0202] In one implementation, the OTA installer can communicate directly with the downstream ECU based on the instruction information issued by the OTA manager, or communicate with each ECU in the vehicle through a distributed gateway to obtain one or more of the software, firmware and hardware information of each ECU, and receive information returned by each ECU.

[0203] For example, when the OTA installer uses unified diagnostic services (UDS), the OTA installer may also be called a UDS installer.

[0204] Here, the OTA manager and OTA installer can be deployed in the following ways: within the vehicle, the OTA manager and OTA installer can be deployed on the same domain controller or on different domain controllers. Here, the OTA manager and OTA installer can exist independently, or the OTA installer can be integrated into the OTA manager, without specific limitation. For example, there is one OTA manager, and the number of OTA installers is related to the number of domain controllers in the vehicle.

[0205] Exemplarily, the domain controller includes but is not limited to: a hardware and software integrated platform for supporting intelligent driving, i.e., an on-board computing platform, such as a mobile data center (MDC); a hardware and software integrated platform for supporting body control and chassis control, such as a vehicle domain controller (VDC); a hardware and software integrated platform for providing on-board multimedia services (e.g., at least one of a head-up display, an instrument panel display, and entertainment audio and video), such as a cockpit domain controller (CDC); a central computing unit, etc., one or more of the following.

[0206] In some possible embodiments, MDC may also be referred to as an advanced driving assistance system domain controller (ADAS DC) or an automatic drive domain controller (AD DC), or may be a hardware and software integrated platform for supporting body control and chassis control.

[0207] In Figure 1, the OTA installer and the distributed gateway communicate via Ethernet or the in-vehicle signal bus, and the distributed gateway and the ECU communicate via Ethernet or the in-vehicle signal bus. It can be understood that the ECU can communicate with the OTA installer through the distributed gateway.

[0208] Here, the in-vehicle signal bus refers to an in-vehicle signal bus other than Ethernet. Exemplarily, the in-vehicle signal bus includes at least one of a controller area network (CAN) bus, a local interconnect network (LIN) bus, a FlexRay bus, a CAN flexible data-rate (CANFD), and a Star Flash wired bus.

[0209] A distributed gateway is also called a vehicle integrated unit (VIU) or a virtual gateway (VGW). The VIU is used to manage the electronic control units (ECUs) in the area where it is located. The VIU can provide nearby access to the corresponding sensors, actuators or ECUs to realize functions such as power supply, electronic fuses, and I / O port isolation. In addition, the VIU has some or all of the functions of a gateway, such as protocol conversion function, protocol encapsulation and forwarding function, and data format conversion function. When the VIU integrates the ECU functions in some vehicle components, the VIU also has an electronic control function, which can provide some or all of the data processing functions and / or control functions for at least one vehicle component. In some possible embodiments, the VIU also has the function of processing data across vehicle components, for example, calculating data obtained from actuators of multiple vehicle components.

[0210] An ECU, also known as an onboard computer or a driving computer, is used to control the vehicle's status and implement various functions. Depending on their function, ECUs in a vehicle include, but are not limited to, at least one of the following: the engine management system (EMS), transmission control unit (TCU), electronic stability program (ESP), battery management system (BMS), motor control unit (MCU), vehicle control unit (VCU), anti-lock brake system (ABS), driver assistance control unit, body control module (BCM), seat ECU, trunk ECU, and entertainment audio and video system.

[0211] For example, after the ECU in Figure 1 completes the flashing of the new version of the software, it performs a reset based on the reset information sent by the OTA installer and starts the new version of the software. If the ECU loses contact with the OTA installer, that is, the ECU and the OTA installer cannot receive each other's messages on the pre-set diagnostic communication link, in this case, the OTA installer cannot obtain the version number of the new version of the software installed by the ECU. Based on the upgrade detection system shown in Figure 1, the embodiment of the present application provides a variety of upgrade detection methods to try to restore the communication between the ECU and the OTA installer, so as to maximize the success rate of the ECU upgrade, which is also conducive to improving the reliability of the OTA upgrade of the entire vehicle. Here, the specific details of each upgrade detection method can be referred to the description of the following method embodiment, which will not be repeated here.

[0212] Depending on the power source of the vehicle, the above-mentioned vehicle can be, for example, a new energy vehicle or a traditional vehicle, among which a traditional vehicle refers to a fuel vehicle, such as a gasoline vehicle, a diesel vehicle, etc., and a new energy vehicle can be, for example, an electric vehicle (EV), a hybrid electric vehicle (HEV), an extended-range electric vehicle (range extended EV), a plug-in hybrid vehicle (Plug-in HEV), a fuel cell vehicle or other new energy vehicles, which are not specifically limited here.

[0213] The upgrade detection system shown in Figure 1 can be applied to any of the following scenarios: fully autonomous driving scenario (i.e., the autonomous driving system performs all operations and the natural driver does not participate in decision-making and operations), human-machine co-driving scenario (i.e., the autonomous driving system and the natural driver jointly complete driving-related operations), and human driving scenario (i.e., the natural driver performs all driving operations).

[0214] The upgrade detection system shown in Figure 1 can be applied to a variety of network types, for example, one or more of the following network types: SparkLink, long term evolution (LTE) network, 5th generation mobile communication technology (5G), wireless local area network (for example, Wi-Fi), Bluetooth (BT), Zigbee, or vehicle-mounted short-range wireless communication network, etc.

[0215] It should be noted that Figure 1 is merely an exemplary architecture diagram and does not limit the number of network elements included in the system shown in Figure 1. Although not shown in Figure 1, Figure 1 may also include other functional entities in addition to the functional entities shown in Figure 1. Furthermore, the methods provided in the embodiments of the present application can be applied to the upgrade detection system shown in Figure 1. Of course, the methods provided in the embodiments of the present application can also be applied to other systems, and the embodiments of the present application are not limited in this regard.

[0216] See Figure 2, which is a flowchart of an upgrade detection method provided in an embodiment of the present application.

[0217] The method shown in Figure 2 can be applied between the first device and the ECU. Here, the first device takes the above-mentioned OTA installer as an example, that is, it is applied between the OTA installer and the ECU, but the embodiment of the present application does not limit the first device to be only an OTA installer. For example, the first device can also be an OTA installer that uses the UDS service, that is, a UDS installer, or it can also be an OTA manager integrated with an OTA installer, or it can also be a domain controller integrated with an OTA installer.

[0218] In some possible embodiments, when the first device and the ECU are not directly connected via Ethernet or an in-vehicle signal bus, the method shown in FIG2 may also be applied to a communication system consisting of the first device, a distributed gateway, and the ECU, wherein the ECU communicates with the first device via the distributed gateway.

[0219] The method includes but is not limited to the following steps:

[0220] S201: Before the first time range, the ECU performs a first reset operation and the ECU loses connection with the OTA installer.

[0221] Here, the first upgrade software is the upgrade software that is newly installed or newly flashed on the ECU. Flashing refers to burning a software program (eg, the first upgrade software) to a specific address in the ECU chip memory.

[0222] The first reset operation is the initial reset performed by the ECU after the first upgrade software has been flashed. The ECU performs the first reset operation based on the first reset message sent by the OTA installer. It is understood that the first reset operation is a reset operation inherent in the traditional ECU upgrade process. That is, after the OTA installer knows that the ECU has completed flashing the first upgrade software, the OTA installer sends the first reset message to the ECU, instructing it to perform the first reset operation.

[0223] Here, the first reset information is carried by the first communication link. The fact that the ECU can receive the first reset information indicates that the ECU and the OTA installer are not disconnected when the OTA installer sends the first reset information.

[0224] During the ECU upgrade process, the first communication link carries information exchanged between the OTA installer and the ECU. For example, the first communication link carries diagnostic messages sent by the OTA installer and the ECU's responses to those messages. Loss of connection between the ECU and the OTA installer means that the two are unable to communicate. This means that the ECU cannot receive information sent by the OTA installer via the first communication link, and the OTA installer cannot receive information sent by the ECU to the OTA installer via the first communication link.

[0225] Exemplarily, the type of the first communication link is a diagnostic communication link, that is, the message carried on the first communication link can be called a diagnostic message.

[0226] For example, the reason why the ECU loses contact with the OTA installer includes at least one of the following faults occurring on the ECU side:

[0227] The first communication link fails to establish a connection after the software upgrade;

[0228] A bug in the OTA protocol stack after a software upgrade renders the diagnostic function inoperable, leading to loss of communication with the OTA installer; and

[0229] After the software upgrade, the sleep and wake-up function is abnormal, resulting in the inability to wake up the communication function after the ECU performs a reset operation.

[0230] That is to say, in the embodiment of the present application, due to at least one of the above-mentioned faults occurring on the ECU side, the ECU loses connection with the OTA installer during the ECU upgrade process.

[0231] Here, at least one of the OTA installer and the ECU can sense a loss of communication between the ECU and the OTA installer. For example, the ECU can sense a loss of communication between itself and the OTA installer, triggering a self-check and self-healing process within the ECU. For details, see the upgrade detection method illustrated in the embodiment of FIG3 below. For another example, after the OTA installer senses a loss of communication with the ECU, it can attempt to restore communication between the ECU and the OTA installer by sending relevant instructions using a redundant communication mechanism. For details, see the upgrade detection method illustrated in the embodiment of FIG4 below, which will not be further described here.

[0232] S202: Within a first time range, the OTA installer performs a first operation.

[0233] In the embodiment of the present application, the first operation is used to restore the communication between the OTA installer and the ECU. Specifically, the first operation is used to restore the communication between the OTA installer and the ECU based on the first communication link.

[0234] Exemplarily, the triggering condition for the OTA installer to execute S202 may be: the OTA installer determines that the ECU and the OTA installer have lost contact. Specifically, before the first time range, the OTA installer sends the aforementioned first reset message to the ECU. After receiving the ECU's response to the first reset message, the OTA installer first sends a first message to the ECU, wherein the first message is used to request the version number of the upgrade software currently used by the ECU. If the OTA installer does not receive a response to the first message from the ECU within a preset time period, the OTA installer determines that the ECU and the OTA installer have lost contact. Here, the first message is carried by the aforementioned first communication link.

[0235] For example, the first time range can be used to indicate a continuous period of time after the ECU loses contact with the OTA installer. The first time range can be represented by two absolute times or by a starting time and a duration. The starting time can be, for example, the time when the ECU loses contact with the OTA installer.

[0236] For the OTA installer, the starting time of the first time range can be the time when the OTA installer determines that the ECU has lost connection with the OTA installer. Optionally, it can also be the time when the OTA installer sends the first reset information, or it can be the time when the OTA installer sends the first message for the first time after sending the first reset information.

[0237] In an embodiment of the present application, the first operation includes repeatedly sending a first message to the ECU. Prior to the first timeframe, the OTA installer did not receive a response from the ECU to the first message after sending the first reset information to the ECU. Therefore, the OTA installer does not know whether the ECU has received the first message. In this case, within the first timeframe, the OTA installer performs the "repeatedly sending the first message" operation. Furthermore, the OTA installer can determine whether communication between the ECU and the OTA installer has been restored based on whether the ECU has received a response to the first message within the first timeframe.

[0238] In one implementation, repeatedly sending the first message includes: repeatedly sending the first message with equal intervals, or sending the first message with increasing intervals, or sending the first message with decreasing intervals, which is not specifically limited here.

[0239] It is understood that while the OTA installer repeatedly sends the first message to the ECU via the first communication link, the OTA installer simultaneously monitors the first communication link for messages from the ECU. This allows real-time monitoring of whether communication between the ECU and the OTA installer via the first communication link has been restored. For example, within a first timeframe, if the OTA installer receives feedback from the ECU on the first communication link regarding the first message, the OTA installer stops sending the first message.

[0240] In one implementation, the first operation also includes: sending a first indication message at least once based on the second communication link, the first indication message is used to indicate that the ECU has lost connection with the OTA installer, or is used to instruct the ECU to perform a second reset operation, and the second communication link is different from the first communication link; or, sending a heartbeat message based on the first communication link.

[0241] Here, the second reset operation is different from the first reset operation. The second reset operation is a reset operation performed after the first reset operation, that is, the second reset operation is an additional reset operation. The second reset operation is used to re-run or start the first upgrade software after OTA flashing.

[0242] Here, the second communication link can be understood as a redundant communication link other than the first communication link. Sending the first indication information to the ECU based on the second communication link can ensure that the ECU can successfully receive the first indication information.

[0243] Here, the number of times the second reset operation is performed is associated with the number of times the first indication information is sent.

[0244] As a possible implementation, the OTA installer sends the first indication information once based on the second communication link. For example, the first indication information is used to indicate that the ECU has lost contact with the OTA installer, so as to trigger the ECU to perform at least one second reset operation.

[0245] As one possible implementation, the OTA installer sends a first instruction message over the second communication link. For example, the first instruction message instructs the ECU to perform a second reset operation. The corresponding ECU then performs the second reset operation based on the first instruction message. In other words, the OTA installer can proactively instruct the ECU to perform an additional second reset operation over the redundant communication link, which helps resolve the issue of ECU loss of connection.

[0246] For example, the heartbeat message is used to indicate that the OTA installer is online or alive, and whether the ECU receives the heartbeat message can serve as a trigger condition for the ECU to determine whether to perform at least one second reset operation or at least one rollback operation.

[0247] In one implementation, the ECU includes a first partition and a second partition, the first partition is used to store the first upgrade software, and the second partition is used to store the second upgrade software. The second upgrade software is the software used by the ECU before the first upgrade software is flashed. The first operation also includes: when the number of times the first indication information is sent reaches a first threshold and the communication between the ECU and the OTA installer has not been restored, the OTA installer sends a rollback message to the ECU based on a second communication link, and the rollback information is used to instruct the ECU to start the second upgrade software. The second communication link is different from the first communication link.

[0248] Illustratively, the communication link carrying the rollback information and the communication link carrying the first indication information may be the same as or different from each other, which is not specifically limited here.

[0249] For example, after the number of times the first indication message is sent reaches a first threshold, the number of times the rollback message is sent is not unlimited, for example, the number of times the rollback message is sent is less than or equal to a second threshold. It is understood that if, after sending the rollback message once, the OTA installer receives a response from the ECU to the first message, the OTA installer may stop sending the rollback message.

[0250] That is to say, if the ECU has a partition storing an old version of software, for example, the second partition of the ECU stores the second upgrade software, the OTA installer can adopt a reset-first-then-rollback strategy to try to restore communication between the ECU and the OTA installer. That is, when the number of times the OTA installer sends the first indication message reaches a first threshold, if the ECU loss of connection problem is still not resolved, a rollback message can be sent to the ECU through a redundant communication link to instruct the ECU to start the second upgrade software. In this way, the success rate of restoring communication between the ECU and the OTA installer can be improved.

[0251] In one implementation, the ECU includes a first partition and a second partition, wherein the first partition is used to store first upgrade software, and the second partition is used to store second upgrade software, the second upgrade software is the software used by the ECU before flashing the first upgrade software, and the first operation also includes: sending rollback information at least once based on a second communication link, the rollback information is used to instruct the ECU to start the second upgrade software, and the second communication link is different from the first communication link.

[0252] It can be seen that, unlike the reset-first-then-rollback strategy adopted by the above-mentioned OTA installer, here, if the ECU has a partition storing the old version of the software, for example, the second partition of the ECU stores the second upgrade software, the OTA installer can also adopt a direct rollback strategy to try to restore the communication between the ECU and the OTA installer. This is conducive to improving the success rate of restoring communication between the ECU and the OTA installer.

[0253] S203: Within the first time range, before the ECU receives the first message sent by the OTA installer, the ECU performs at least one second reset operation.

[0254] Here, the second reset operation is different from the first reset operation, and the second reset operation is a reset operation performed after the first reset operation. The second reset operation is used to re-run or start the first upgrade software after OTA flashing.

[0255] In the embodiment of the present application, the triggering condition for the ECU to perform at least one second reset operation is any of the following conditions:

[0256] (1) Before the first time range, within a first preset time period after the ECU performs the first reset operation, the ECU does not receive the first message sent by the OTA installer;

[0257] (2) Within a second preset time period after the ECU performs the first reset operation, the ECU does not receive a heartbeat message sent by the OTA installer;

[0258] (3) The ECU receives a first indication message, where the first indication message is used to indicate that the ECU has lost contact with the OTA installer, or to indicate that the ECU initiates a second reset operation; or

[0259] (4) The ECU receives power-off indication information, which is used by the ECU to perform a second reset operation.

[0260] Exemplarily, the first indication information is upgrade indication information carrying an upgrade package.

[0261] Exemplarily, the power-off indication information may be included in the first indication information.

[0262] Here, the first preset time length and the second preset time length may be equal or unequal. Exemplarily, the first preset time length or the second preset time length is one detection cycle.

[0263] For the above condition (1), after the ECU performs the first reset operation to successfully start the first upgrade software, it can detect whether it has lost contact with the OTA installer by setting a mechanism for the ECU to autonomously monitor the first message on the first communication link. For example, if the ECU does not receive the first message within the above first preset time period, it determines that it has lost contact with the OTA installer.

[0264] For condition (2), the OTA installer can periodically send heartbeat messages to the ECU based on the first communication link. The heartbeat message is used to inform the other party (i.e., ECU) that the OTA installer is alive. If the ECU can receive the heartbeat message, it means that communication between the ECU and the OTA installer has been restored, and it also means that the ECU has not lost connection.

[0265] For condition (3), the first indication information may be sent to the ECU when the OTA installer determines that the ECU has lost contact with the OTA installer. For example, the first indication information may be upgrade indication information carrying an upgrade package.

[0266] Here, the number of times the second reset operation is performed is associated with the number of times the ECU receives the first indication information.

[0267] For example, the ECU may be triggered to perform multiple second reset operations by receiving the first indication information once.

[0268] For another example, the ECU performs the second reset operation each time it receives the first indication information.

[0269] It is understood that to ensure that the first indication information is successfully received by the ECU, the first indication information is carried by the second communication link, which is different. For details about the first and second communication links, please refer to the corresponding content below. It can be seen that if the ECU loses communication with the OTA installer, the indication information can be carried by other redundant communication links to ensure that the ECU receives the indication information, thereby facilitating the restoration of communication between the ECU and the OTA installer.

[0270] For condition (4), the power-off indication information issued during the vehicle inspection process can also trigger the ECU to perform the second reset operation, which is beneficial to improving the success rate of restoring communication between the ECU and the OTA installer based on the first communication link.

[0271] In the embodiment of the present application, the first communication link includes a diagnostic communication link based on Ethernet and / or a diagnostic communication link based on a first in-vehicle signal bus.

[0272] For example, when the ECU is directly connected to a domain controller integrated with an OTA installer, or when the ECU is connected to the domain controller integrated with an OTA installer via a distributed gateway and the communication connection methods between the ECU and the distributed gateway, and between the distributed gateway and the OTA installer, are the same, the first communication link is an Ethernet-based diagnostic communication link or a diagnostic communication link based on the first in-vehicle signal bus. If the ECU is connected to the domain controller integrated with an OTA installer via a distributed gateway and the communication connection methods between the ECU and the distributed gateway, and between the distributed gateway and the OTA installer, are different, the first communication link includes an Ethernet-based diagnostic communication link and a diagnostic communication link based on the first in-vehicle signal bus.

[0273] For example, the in-vehicle signal bus includes a wired signal bus such as a CAN bus, a LIN bus, and a FlexRay bus. For example, a diagnostic communication link based on a CAN bus may be referred to as a DOCAN link, and a diagnostic communication link based on a LIN bus may be referred to as a DOLIN link.

[0274] In one implementation, the first communication link is an Ethernet-based diagnostic communication link, and the second communication link includes:

[0275] At least one of a service communication link based on a second in-vehicle signal bus and a service communication link based on Ethernet; or

[0276] A diagnostic communication link based on a second in-vehicle signal bus.

[0277] It can be understood that the first communication link is an Ethernet-based diagnostic communication link, which means that the OTA installer and the distributed gateway, as well as the distributed gateway and the ECU, are connected via Ethernet. Based on Figure 1 , it can be seen that the OTA installer communicates with the ECU via the distributed gateway. The following examples 1 to 6 specifically illustrate the second communication link:

[0278] Example 1: The second communication link is an Ethernet-based service communication link.

[0279] Example 2: The second communication link is a service communication link based on in-vehicle signal bus 1. Example 2 is feasible only if both the OTA installer and the distributed gateway, and the distributed gateway and the ECU, are connected via in-vehicle signal bus 1. In this case, the second in-vehicle signal bus is equivalent to in-vehicle signal bus 1.

[0280] Example 3: The second communication link includes a service communication link based on in-vehicle signal bus 1 and a service communication link based on in-vehicle signal bus 2. In-vehicle signal bus 1 is used to connect the OTA installer and the distributed gateway, and in-vehicle signal bus 2 is used to connect the distributed gateway and the ECU. Alternatively, in-vehicle signal bus 2 is used to connect the OTA installer and the distributed gateway, and in-vehicle signal bus 1 is used to connect the distributed gateway and the ECU. In this case, the second in-vehicle signal bus is equivalent to including in-vehicle signal bus 1 and in-vehicle signal bus 2.

[0281] Example 4: The second communication link includes a business communication link based on the in-vehicle signal bus 1 and a business communication link based on Ethernet, wherein the in-vehicle signal bus 1 is used to connect the OTA installer with the distributed gateway and Ethernet is used to connect the distributed gateway with the ECU, or, Ethernet is used to connect the OTA installer with the distributed gateway and the in-vehicle signal bus 1 is used to connect the distributed gateway with the ECU.

[0282] Example 5: The second communication link includes a diagnostic communication link based on in-vehicle signal bus 1. Example 5 is only feasible if both the OTA installer and the distributed gateway, and the distributed gateway and the ECU, are connected via in-vehicle signal bus 1. In this case, the second in-vehicle signal bus is equivalent to in-vehicle signal bus 1.

[0283] Example 6: The second communication link includes a diagnostic communication link based on in-vehicle signal bus 1 and a diagnostic communication link based on in-vehicle signal bus 2. In-vehicle signal bus 1 is used to connect the OTA installer and the distributed gateway, and in-vehicle signal bus 2 is used to connect the distributed gateway and the ECU. Alternatively, in-vehicle signal bus 2 is used to connect the OTA installer and the distributed gateway, and in-vehicle signal bus 1 is used to connect the distributed gateway and the ECU. In this case, the second in-vehicle signal bus is equivalent to including in-vehicle signal bus 1 and in-vehicle signal bus 2.

[0284] In one implementation, the first communication link is a diagnostic communication link based on a first in-vehicle signal bus, and the second communication link includes:

[0285] At least one of a service communication link based on a second in-vehicle signal bus and a service communication link based on Ethernet; or

[0286] At least one of a diagnostic communication link based on a third in-vehicle signal bus and a diagnostic communication link based on Ethernet, the third in-vehicle signal bus being different from the first in-vehicle signal bus.

[0287] Here, the second in-vehicle signal bus may be the same as or different from the first in-vehicle signal bus, which is not specifically limited herein.

[0288] It can be understood that, considering the in-vehicle signal bus connecting the OTA installer and the distributed gateway, and the in-vehicle signal bus connecting the distributed gateway and the ECU, the two can be the same or different. The embodiment of the present application does not limit the number of in-vehicle signal buses included in the first in-vehicle signal bus. For example, the first in-vehicle signal bus is a CAN bus, and for another example, the first in-vehicle signal bus includes a CAN bus and a LIN bus.

[0289] In one implementation, the ECU is communicatively connected to the OTA installer via a distributed gateway within the vehicle, wherein the first communication link includes an Ethernet-based diagnostic communication link and a diagnostic communication link based on a first in-vehicle signal bus, and the second communication link includes:

[0290] At least one of a service communication link based on a second in-vehicle signal bus and a service communication link based on Ethernet; or

[0291] a third communication link and a fourth communication link, wherein the third communication link is used to connect the OTA installer and the distributed gateway, and the fourth communication link is used to connect the distributed gateway and the ECU;

[0292] Among them, if the Ethernet-based diagnostic communication link in the first communication link is used to connect the OTA installer and the distributed gateway, and the diagnostic communication link based on the first in-vehicle signal bus in the first communication link is used to connect the distributed gateway and the ECU, then when the third communication link is a diagnostic communication link based on any in-vehicle signal bus, the fourth communication link is an Ethernet-based diagnostic communication link or a diagnostic communication link based on the third in-vehicle signal bus, and the third in-vehicle signal bus is different from the first in-vehicle signal bus; or, when the third communication link is a business communication link based on Ethernet or any in-vehicle signal bus, the fourth communication link is a business communication link based on Ethernet or any in-vehicle signal bus. Similarly, if the diagnostic communication link based on the first in-vehicle signal bus in the first communication link is used to connect the OTA installer and the distributed gateway, and the diagnostic communication link based on Ethernet in the first communication link is used to connect the distributed gateway and the ECU, then when the third communication link is a diagnostic communication link based on Ethernet or a diagnostic communication link based on the third in-vehicle signal bus, the fourth communication link is a diagnostic communication link based on any in-vehicle signal bus, and the third in-vehicle signal bus is different from the first in-vehicle signal bus; or, the third communication link is a business communication link based on Ethernet or any in-vehicle signal bus, and the fourth communication link is a business communication link based on Ethernet or any in-vehicle signal bus.

[0293] Table 1 more clearly illustrates various possible scenarios for the first and second communication links. Table 1 primarily shows the correspondence between the first and second communication links, as well as their types. As can be seen from Table 1, the first communication link is a diagnostic communication link, while the second communication link is either a diagnostic communication link or a service communication link. In Table 1, the distributed gateway uses the VIU as an example.

[0294] In Table 1, when the first communication link is a diagnostic communication link based on Ethernet, if the type of the second communication link is diagnosis, the second communication link is a diagnostic communication link based on the in-vehicle signal bus; if the type of the second communication link is service, the second communication link includes a service communication link based on Ethernet and / or the in-vehicle signal bus.

[0295] In Table 1, when the first communication link is a diagnostic communication link based on the in-vehicle signal bus 1, if the type of the second communication link is diagnosis, the second communication link includes a diagnostic communication link based on Ethernet and / or an in-vehicle signal bus other than the in-vehicle signal bus 1; if the type of the second communication link is service, the second communication link includes a service communication link based on Ethernet and / or the in-vehicle signal bus.

[0296] In Table 1, the first communication link includes a diagnostic communication link based on the in-vehicle signal bus 1 and a diagnostic communication link based on the in-vehicle signal bus 2, wherein the diagnostic communication link based on the in-vehicle signal bus 1 is used to connect the OTA installer and the VIU, and the diagnostic communication link based on the in-vehicle signal bus 2 is used to connect the VIU and the ECU. If the type of the second communication link is diagnostic, the communication link in the second communication link for connecting the OTA installer and the VIU is a diagnostic communication link based on Ethernet or an in-vehicle signal bus other than the in-vehicle signal bus 1, and the communication link in the second communication link for connecting the VIU and the ECU is a diagnostic communication link based on Ethernet or an in-vehicle signal bus other than the in-vehicle signal bus 2; if the type of the second communication link is service, the second communication link includes a service communication link based on Ethernet and / or the in-vehicle signal bus.

[0297] In Table 1, the first communication link includes a diagnostic communication link based on Ethernet and a diagnostic communication link based on the in-vehicle signal bus 1, wherein the diagnostic communication link based on Ethernet is used to connect the OTA installer and the VIU, and the diagnostic communication link based on the in-vehicle signal bus 1 is used to connect the VIU and the ECU. If the type of the second communication link is diagnostic, the communication link in the second communication link used to connect the OTA installer and the VIU is a diagnostic communication link based on the in-vehicle signal bus, and the communication link in the second communication link used to connect the VIU and the ECU is a diagnostic communication link based on Ethernet or an in-vehicle signal bus other than the in-vehicle signal bus 1; if the type of the second communication link is service, the second communication link includes a service communication link based on Ethernet and / or the in-vehicle signal bus.

[0298] Table 1

[0299] In Table 1, the first communication link includes a diagnostic communication link based on the in-vehicle signal bus 1 and a diagnostic communication link based on Ethernet, wherein the diagnostic communication link based on the in-vehicle signal bus 1 is used to connect the OTA installer and the VIU, and the diagnostic communication link based on Ethernet is used to connect the VIU and the ECU. If the type of the second communication link is diagnostic, the communication link in the second communication link used to connect the OTA installer and the VIU is a diagnostic communication link based on Ethernet or an in-vehicle signal bus other than the in-vehicle signal bus 1, and the communication link in the second communication link used to connect the VIU and the ECU is a diagnostic communication link based on the in-vehicle signal bus; if the type of the second communication link is service, the second communication link includes a service communication link based on Ethernet and / or the in-vehicle signal bus.

[0300] It can be understood that Table 1 is only for making the above description clearer and more intuitive, and does not limit the correspondence between the first communication link, the second communication link, and the type of the second communication link to only what is shown in Table 1.

[0301] It is understood that the second communication link corresponding to the first communication link shown in Table 1 can serve as a redundant communication link only if the connections between the OTA installer and the distributed gateway (e.g., VIU), and between the distributed gateway and the ECU, are deployed with corresponding Ethernet and / or in-vehicle signal buses. For example, if the first communication link is an Ethernet-based diagnostic communication link and the second communication link is a CAN-based diagnostic communication link, the second communication link can serve as a redundant communication link for the first communication link only if the connections between the OTA installer and the distributed gateway, and between the distributed gateway and the ECU, are both connected via a CAN bus.

[0302] Here, setting the ECU to perform at least one second reset operation within the first time range after the first reset operation is beneficial to improving the success rate of restoring communication between the ECU and the OTA installer based on the first communication link, and is also beneficial to improving the success rate of ECU upgrades and the reliability of vehicle upgrades.

[0303] S204: Within the first time range, the ECU sends a second message to the OTA installer, where the second message is associated with the first message.

[0304] In one implementation, the second message includes the version number of the first upgrade software. In this case, it indicates that the ECU has restored communication between the ECU and the OTA installer by performing the second reset operation.

[0305] In another implementation, the second message includes the version number of the second upgrade software. In this case, it indicates that the ECU has restored communication between the ECU and the OTA installer by launching the second upgrade software (or performing a rollback operation).

[0306] Here, the second message is carried by the above-mentioned first communication link.

[0307] In one implementation, the ECU sends the second message to the OTA installer, including: the ECU receives the first message, and in response to the first message, the ECU sends the second message to the OTA installer. In this case, the second message is sent only after the ECU receives the first message.

[0308] Furthermore, the second message is a heartbeat message, and the second message can also be used to indicate that the ECU is online or alive.

[0309] S205: Within the first time range, if the ECU and the OTA installer resume communication, the OTA installer receives the second message.

[0310] In one implementation, the OTA installer may also determine the upgrade result of the ECU based on the second message.

[0311] Specifically, the ECU upgrade result is determined based on the second message, including: if the version number included in the second message is the same as the version number of the first upgrade software, the ECU upgrade is determined to be successful; or if the version number included in the second message is different from the version number of the first upgrade software, or if the version number included in the second message is the same as the version number of the second upgrade software, the ECU upgrade is determined to have failed. In this way, the OTA installer can accurately know the ECU upgrade result based on the second message. When unifying the software version used by the entire vehicle, it can accurately decide whether to perform an upgrade or rollback on a specific ECU. In this way, the business can operate normally in a working environment with compatible software versions, which is conducive to improving the reliability of vehicle upgrades.

[0312] In some possible embodiments, after the OTA installer determines that the ECU upgrade has failed, the OTA installer may also send an upgrade instruction message to the ECU, instructing the ECU to re-execute the OTA upgrade based on the first upgrade software. In this way, if communication between the ECU and the OTA installer is restored, the ECU re-flashes the first upgrade software based on the upgrade instruction message, which helps improve the success rate of the ECU upgrade and also helps unify the various versions of ECU software throughout the vehicle, thereby improving the reliability of the vehicle upgrade.

[0313] In some possible embodiments, if the OTA installer does not receive the second message sent by the ECU within the first timeframe, the OTA installer may also send feedback to the OTA administrator, where the feedback indicates that the ECU and the OTA installer have lost contact. The OTA administrator can then perform a full vehicle inspection or request manual intervention to resolve the disconnection between the ECU and the OTA installer.

[0314] It can be seen that after the ECU performs a reset operation and successfully starts the newly installed upgrade software, if the ECU loses connection with the OTA installer, adding a reset operation to the ECU after successfully starting the upgrade software, or notifying the ECU to perform a reset operation through a redundant link, will help improve the success rate of repairing the loss of connection between the ECU and the OTA installer, and will also help improve the success rate and reliability of ECU upgrades and the success rate of vehicle upgrades.

[0315] The following describes an upgrade detection method in which the ECU initiates the upgrade detection process.

[0316] See FIG3 , which is a flowchart of another upgrade detection method provided in an embodiment of the present application.

[0317] This method can be applied between the first device and ECU1. Here, the first device takes the above-mentioned UDS installer as an example. The UDS installer is an example of an OTA installer, that is, it is applied between the UDS installer and the ECU. However, the embodiment of the present application does not limit the first device to be only a UDS installer. For example, the first device can also be an OTA installer that uses other diagnostic communication protocols, or it can also be an OTA manager integrated with an OTA installer, or it can also be a domain controller integrated with an OTA installer.

[0318] In some possible embodiments, when the first device and ECU1 are not directly connected via Ethernet or an in-vehicle signal bus, the method shown in FIG3 may also be applied to a communication system consisting of the first device, a distributed gateway, and ECU1, wherein ECU1 communicates with the first device via the distributed gateway.

[0319] In the embodiment of FIG3 , the first communication link is a DOIP link as an example. That is, during the upgrade process of the pre-set ECU, the communication between the UDS installer and the ECU is based on the DOIP link. However, the embodiment of the present application is not limited to the first communication link being only a DOIP link. The method includes but is not limited to the following steps:

[0320] S301: ECU1 performs a first reset operation based on a first reset message sent by a UDS installer. If a preset condition is met, ECU1 starts performing a second reset operation at least once within at least one first detection cycle.

[0321] Here, the ECU performs the first reset operation, which means that the ECU starts or runs the first upgrade software once. The description of the first reset operation and the second reset operation can be specifically referred to the description of the corresponding content in the embodiment of Figure 2, and will not be repeated here.

[0322] Here, the first detection period may also be referred to as the self-healing time duration of the ECU 1 .

[0323] Exemplarily, satisfying the preset condition means that ECU 1 has determined that it has lost contact with the UDS installer, thereby triggering ECU 1 to execute S303. For example, the first communication link is a DOIP link. Loss of contact between ECU 1 and the UDS installer indicates that the ECU and the UDS installer are unable to communicate. Specifically, the ECU cannot receive information sent by the UDS installer to the ECU via the DOIP link, and the UDS installer cannot receive information sent by the ECU to the UDS installer via the DOIP link.

[0324] The preset condition is any of the following:

[0325] (1) Within a first preset time period after ECU1 performs the first reset operation, ECU1 does not receive the first message sent by the UDS installer;

[0326] (2) Within a second preset time period after ECU1 performs the first reset operation, ECU1 does not receive a heartbeat message sent by the UDS installer;

[0327] (3) ECU1 receives a first indication message, the first indication message is used to indicate that ECU1 has lost contact with the UDS installer, or is used to indicate that ECU1 starts to perform a second reset operation; or,

[0328] (4) ECU1 receives the power-off indication information, which is used by ECU1 to perform the second reset operation.

[0329] The above condition (3) specifically means that before at least one first detection cycle, within a third preset time period after ECU1 performs the first reset operation, if ECU1 receives the first indication information, it can trigger ECU1 to perform at least one second reset operation.

[0330] Here, the preset condition is the trigger condition in S203 of the embodiment of FIG. 2 , and reference may be made to the corresponding description of the trigger condition.

[0331] Exemplarily, the first indication information may be obtained by ECU1 from the UDS installer, the OTA manager, and the vehicle control device. Here, when the first indication information is obtained by ECU1 from the OTA manager, the UDS installer is integrated into the OTA manager. The vehicle control device may be, for example, a hardware and software integrated platform for supporting intelligent driving, i.e., an on-board computing platform, such as a mobile data center (MDC), an advanced driving assistance system domain controller (ADAS DC), or an automatic drive domain controller (AD DC), or may be a hardware and software integrated platform for supporting body control and chassis control.

[0332] For example, since the first communication link is a DOIP link, in order to ensure that ECU1 can receive the first indication information, the first indication information is carried through the following link:

[0333] At least one of a service communication link based on an in-vehicle signal bus and a service communication link based on Ethernet; or

[0334] Diagnostic communication link based on the in-vehicle signal bus.

[0335] Taking the example of ECU1 obtaining the first instruction information from the UDS installer, assuming that ECU1 obtains the first instruction information from the UDS installer through the distributed gateway, the following describes the carrying method of the first instruction information in detail, combining possible connection methods between the UDS installer and the distributed gateway, and between the distributed gateway and ECU1:

[0336] Connection method 1: The UDS installer and the distributed gateway, as well as the distributed gateway and ECU1 are connected via Ethernet.

[0337] In this case, the first instruction information is carried by the Ethernet-based service communication link. Specifically, the UDS installer can send the first instruction information to the distributed gateway via the Ethernet-based service communication link, and the distributed gateway sends the first instruction information to ECU1 via the Ethernet-based service communication link.

[0338] Connection method 2: The UDS installer is connected to the distributed gateway via Ethernet, and the distributed gateway is connected to ECU1 via the in-vehicle signal bus.

[0339] In this case, when the UDS installer sends the first instruction information to ECU1, the first instruction information is first carried by the Ethernet-based service communication link and then by the service communication link based on the in-vehicle signal bus. Specifically, the UDS installer can send the first instruction information to the distributed gateway via the Ethernet-based service communication link, and the distributed gateway sends the first instruction information to ECU1 via the service communication link based on the in-vehicle signal bus.

[0340] Connection method 3: The UDS installer is connected to the distributed gateway via the in-vehicle signal bus, and the distributed gateway is connected to ECU1 via Ethernet.

[0341] In this case, when the UDS installer sends the first instruction information to ECU1, the first instruction information is first carried by the service communication link based on the in-vehicle signal bus and then by the service communication link based on Ethernet. Specifically, the UDS installer can send the first instruction information to the distributed gateway via the service communication link based on the in-vehicle signal bus, and the distributed gateway can send the first instruction information to ECU1 via the service communication link based on Ethernet.

[0342] Connection method 4: The UDS installer and the distributed gateway, as well as the distributed gateway and ECU1 are connected through the in-vehicle signal bus.

[0343] In one case, the first indication information is carried by a service communication link based on the in-vehicle signal bus. Specifically, the UDS installer can send the first indication information to the distributed gateway via the service communication link based on the in-vehicle signal bus, and the distributed gateway sends the first indication information to ECU1 via the service communication link based on the in-vehicle signal bus.

[0344] In another case, the first indication information is carried by a diagnostic communication link based on the in-vehicle signal bus. Specifically, the UDS installer can send the first indication information to the distributed gateway via the diagnostic communication link based on the in-vehicle signal bus, and the distributed gateway sends the first indication information to ECU1 via the diagnostic communication link based on the in-vehicle signal bus.

[0345] The first indication information is not carried by the DOIP link, but is carried by the link shown above, to ensure that the ECU1 can receive the first indication information, thereby triggering the ECU1 to execute S303.

[0346] S302: Within a preset verification time, the UDS installer repeatedly sends the first message to ECU1 based on the DOIP link.

[0347] Here, the first message is used to request to obtain the version number of the upgrade software currently used by ECU1.

[0348] Here, the preset verification time length is equivalent to the first time range in the embodiment of FIG. 2 .

[0349] Exemplarily, repeatedly sending the first message may be: repeatedly sending the first message with equal intervals, or sending the first message with increasing intervals, or sending the first message with decreasing intervals.

[0350] Exemplarily, the UDS installer repeatedly sends the first message as follows: the UDS installer sends the first message to the ECU based on the DOIP link at time t1, time t2, time t3, time t4, ... In one case, the interval between any two adjacent sending times of the first message may be equal, for example, (t2-t1)=(t3-t2)=(t4-t3)=...; in another case, the interval between any two adjacent sending times of the first message may also be unequal, for example, the sending interval of the first message may become longer and longer, that is, (t2-t1)<(t3-t2)<(t4-t3)<..., and for another example, the sending interval of the first message may become shorter and shorter, that is, (t2-t1)>(t3-t2)>(t4-t3)>...

[0351] It is understandable that within the preset verification time, if the UDS installer receives a response from the ECU to a first message sent by the UDS installer on the DOIP link, the UDS installer may stop sending the first message to ECU1.

[0352] Here, the preset verification time includes the at least one first detection period. For example, the relationship between the preset verification time and the at least one first detection period can satisfy the following formula (1): T = T1*n+Δt Formula (1)

[0353] Wherein, T represents the preset verification time length, T1 represents a first detection cycle, n represents the number of the at least one first detection cycle, and Δt represents the reserved time length, that is, a margin is left.

[0354] S303: Within at least one first detection cycle, before receiving the first message, the ECU 1 performs at least one second reset operation, wherein the at least one second reset operation corresponds to at least one first detection cycle.

[0355] Exemplarily, the at least one second reset operation corresponds to at least one first detection cycle, which means that each time the ECU 1 performs the second reset operation, a first detection cycle is started.

[0356] For example, assuming that the duration of each first detection cycle is T1, see Figure 3, ECU1 performs the first second reset operation. If ECU1 does not receive the first message sent by the UDS installer on the DOIP link within T1 after performing the first second reset operation, then ECU1 performs the second second reset operation. If ECU1 does not receive the first message sent by the UDS installer on the DOIP link within T1 after performing the second second reset operation, then ECU1 performs the third second reset operation, ..., until ECU1 receives the first message sent by the UDS installer on the DOIP link within T1 after a certain second reset operation, or the number of times ECU1 performs the second reset operation reaches the first threshold, ECU1 stops performing the second reset operation.

[0357] For another example, assuming that within T1 time after ECU1 performs the first second reset operation, ECU1 receives the first message sent by the UDS installer on the DOIP link, it means that the second reset operation of ECU1 has restored the communication between ECU1 and the UDS installer based on the DOIP link, so ECU1 does not need to perform the above-mentioned second second reset operation.

[0358] That is to say, when the ECU loses connection with the UDS installer, the ECU performing an additional second reset operation is helpful in solving the ECU loss of connection problem, and by setting the ECU to attempt multiple second reset operations, the success rate of restoring communication between the ECU and the UDS installer can be improved.

[0359] Here, the execution order of S302 and S303 is not limited, that is, they can be executed simultaneously, one after the other, or one after the other. For example, when ECU1 executes the first second reset operation, the UDS installer in S302 also starts sending the first message; or, after ECU1 autonomously executes the first second reset operation, the UDS installer in S302 sends the first message; or, after the UDS installer sends the first message in S302, ECU1 executes the first second reset operation.

[0360] S304: Within at least one first detection cycle, ECU1 receives a first message. In response to the first message, ECU1 sends a second message to the UDS installer based on the DOIP link.

[0361] The second message includes the version number of the first upgrade software.

[0362] S305: Within the preset verification time, if the ECU1 and the UDS installer resume communication, the UDS installer receives the second message on the DOIP link.

[0363] Here, when the ECU1 resumes communication with the UDS installer, the delay between the moment when the ECU1 sends the second message to the UDS installer and the moment when the UDS installer receives the second message can be ignored.

[0364] Furthermore, the version number of the upgrade software carried in the second message is the same as the version number of the first upgrade software, confirming that the UDS installer has successfully upgraded ECU1. In other words, upon receiving the second message, the UDS installer can obtain the version number of the latest upgrade software installed on ECU1, thereby confirming that ECU1 has been correctly upgraded to the latest version and confirming that the upgrade was successful. This improves the reliability of ECU upgrades and also helps improve the success rate and reliability of vehicle upgrades.

[0365] In some possible embodiments, if the number of at least one second reset operation reaches a first threshold, indicating that ECU1 has not received the first message on the DOIP link within at least one first detection period, ECU1 then stops monitoring the first message on the DOIP link. In this case, since ECU1 has not received the first message, it will not send the second message to the UDS installer. If the UDS installer does not receive the second message on the DOIP link within a preset verification period, the UDS installer can send feedback information to the OTA administrator, causing the OTA administrator to perform a full vehicle test in an attempt to restore communication between the UDS installer and ECU1. For details, please refer to the relevant description of the embodiment of Figure 5 below. The feedback information is used to indicate that ECU1 has lost contact with the UDS installer.

[0366] In some possible embodiments, ECU1 includes a first partition and a second partition, wherein the first partition is used to store the first upgrade software, and the second partition is used to store the second upgrade software, and the second upgrade software is the software used by the ECU before the first upgrade software is flashed. If the number of at least one second reset operation reaches a first threshold, the ECU can also start the second upgrade software (or perform a rollback operation, which is used to switch from the first partition to the second partition to start the second upgrade software) to try to restore communication between ECU1 and the UDS installer; during the second detection cycle, if ECU1 and the UDS installer have restored communication, ECU1 receives the first message on the DOIP link, and ECU1 sends a third message to the UDS installer based on the first communication link, and the third message includes the version number of the second upgrade software. Accordingly, within the preset verification time, if ECU1 and the UDS installer resume communication, the UDS installer receives the third message on the DOIP link. Since the version number included in the third message is different from the version number of the first upgrade software, the UDS installer can also determine that the ECU1 upgrade has failed based on the third message. That is, the UDS installer can accurately know the upgrade result of ECU1, which facilitates subsequent accurate decision-making to ensure the uniformity of the software version used in the entire vehicle.

[0367] Here, the embodiment of the present application does not limit the number of times ECU1 continuously performs the rollback operation.

[0368] It can be understood that for UDS installers, when ECU1 performs a rollback operation after performing at least one second reset operation, the above-mentioned preset inspection time length includes not only the above-mentioned at least one first detection period, but also the second detection period corresponding to the rollback operation performed by ECU1.

[0369] Furthermore, when the UDS installer determines that the ECU1 upgrade has failed based on the received third message, the UDS installer can also send upgrade indication information to ECU1 based on the DOIP link. The upgrade indication information is used to instruct ECU1 to re-execute the OTA upgrade based on the first upgrade software, which is conducive to improving the success rate of the ECU upgrade.

[0370] Furthermore, if the UDS installer does not receive the above-mentioned third message on the DOIP link within the preset verification time, the UDS installer can also send feedback information to the OTA manager so that the OTA manager can perform a whole vehicle inspection to try to restore the communication between the UDS installer and ECU1. For details, please refer to the relevant description of the embodiment of Figure 5 below. The feedback information is used to indicate that ECU1 has lost contact with the UDS installer.

[0371] In some possible embodiments, if ECU1 has a partition storing older software versions, such as the second partition of ECU1 used to store the aforementioned second upgrade software, then if the preset conditions in S301 are met, ECU1 may not be triggered to perform at least one second reset operation, i.e., S303 will not be executed. Instead, ECU1 may be triggered to perform at least one rollback operation (or initiate at least one second upgrade software operation) within at least one detection cycle, with each rollback operation corresponding to one detection cycle. In this case, the UDS installer can monitor the DOIP link for a third message from ECU1 within a preset verification period. Upon receiving the third message, the installer can accurately determine that the ECU1 upgrade failed, i.e., the ECU was not correctly upgraded to the latest version. Thus, during the ECU upgrade process, the transmission of the third message helps the OTA installer collect statistics on the ECU upgrade status, facilitating subsequent accurate decision-making, such as determining which ECUs need to be rolled back or re-upgraded, thereby ensuring consistent ECU version matching across the vehicle and the normal operation of various services.

[0372] As can be seen, by implementing the embodiments of the present application, the ECU performs a second reset operation after the first reset operation, which helps resolve the issue of lost communication between the ECU and the UDS installer. Furthermore, by configuring the ECU to attempt multiple second reset operations, the success rate of restoring communication between the ECU and the UDS installer can be improved. Furthermore, if the ECU has a partition storing older software versions, the ECU can employ a reset-then-rollback strategy, or a direct rollback strategy, to restore communication between the ECU and the UDS installer. This allows the ECU to roll back to the older software version prior to the upgrade, improving the reliability of vehicle upgrades.

[0373] The following describes the upgrade detection method in which the UDS installer initiates the upgrade detection process.

[0374] See FIG. 4 , which is a flowchart of another upgrade detection method provided in an embodiment of the present application.

[0375] This method can be applied between the first device and ECU1. Here, the first device takes the UDS installer as an example, that is, it is applied between the UDS installer and the ECU. However, the embodiment of the present application does not limit the first device to be only the UDS installer. For other possible forms of the first device, please refer to the description of the first device in the embodiment of Figure 2.

[0376] In some possible embodiments, when the first device and ECU1 are not directly connected via Ethernet or an in-vehicle signal bus, the method shown in FIG4 may also be applied to a communication system consisting of the first device, a distributed gateway, and ECU1, wherein ECU1 communicates with the first device via the distributed gateway.

[0377] The method includes but is not limited to the following steps:

[0378] S401: After the UDS installer sends the first reset message, if no response to the first message from the ECU1 is received on the first communication link (eg, DOIP link), the UDS installer starts sending the first message and the first indication message.

[0379] Here, in the embodiment of FIG4, the first communication link is exemplified by a DOIP link, but the present embodiment is not limited to the first communication link being a DOIP link. Other possible forms of the first communication link can be referred to the description of the first communication link in Table 1 of the embodiment of FIG2, and will not be repeated here.

[0380] Here, the first message is used to request the version number of the upgrade software currently used by the ECU. The first message is carried by the first communication link.

[0381] Exemplarily, the first instruction information is used to instruct the ECU to perform the second reset operation. The first instruction information is carried by a second communication link, which is different from the first communication link.

[0382] For example, after the UDS installer sends the first reset message, if it does not receive feedback from ECU1 on the DOIP link regarding the first message, the UDS installer determines that ECU1 and the UDS installer have lost contact. The UDS installer then starts sending the first message and the first instruction message, triggering the UDS installer to execute S402 and S403. For details on sending the first instruction message, see the description of S402 below, and for details on sending the first message, see the description of S403 below.

[0383] For example, before the UDS installer determines that ECU1 has lost contact with the UDS installer, the interaction process between the UDS installer and ECU1 is as follows: After the UDS installer learns that ECU1 has completed flashing the first upgrade software, it first sends a first reset message to ECU1 over the DOIP link. ECU1 performs a first reset operation based on the first reset message to start the first upgrade software, and then sends a response message to the UDS installer over the DOIP link. This response message informs the UDS installer that ECU1 has performed the first reset operation based on the first reset message. After receiving this response message, the UDS installer sends a first message to ECU1 over the DOIP link and waits for ECU1's response to the first message. The first message is used to request the version number of the upgrade software currently used by ECU1. In this case, the time when ECU1 and the UDS installer lose contact can be, for example, after ECU1 sends the response message to the first reset message to the UDS installer (i.e., ECU1 does not receive the first message) or after ECU1 receives the first message.

[0384] Accordingly, the reasons why the UDS installer did not receive ECU1's feedback on the first message on the DOIP link include: ECU1 did not receive the first message on the DOIP link due to loss of connection, and therefore did not send a response to the first message to the UDS installer, so the OTA installer did not receive ECU's response to the first message; or, ECU1 had received the first message on the DOIP link and sent a response to the first message to the UDS installer, but due to ECU1 losing connection, the UDS installer did not receive ECU1's feedback on the first message on the DOIP link.

[0385] S402: Within at least one detection cycle, the UDS installer sends first instruction information to the ECU 1 at least once based on the second communication link.

[0386] Here, the first instruction information is used to instruct the ECU 1 to perform the second reset operation. That is, within the at least one detection cycle, the ECU 1 performs the second reset operation at least once.

[0387] For example, in Figure 4, a dotted line with an arrow indicates sending a first indication message. It can be seen that each time the UDS installer sends a first indication message, a detection cycle is started. For example, the number of times the first indication message is sent is the same as the number of detection cycles started.

[0388] For example, the error between the time when the UDS installer sends the first instruction information and the time when the ECU 1 receives the first instruction information can be ignored.

[0389] Here, the second communication link is different from the first communication link. This ensures that the ECU1 can receive the first instruction information, so that the ECU1 performs the second reset operation based on the first instruction information, which is conducive to improving the success rate of restoring communication between the ECU1 and the UDS installer based on the first communication link.

[0390] When the first communication link is a DOIP link, the second communication link may be a link shown in any of the following situations:

[0391] Case 1: Diagnostic communication link based on any in-vehicle signal bus;

[0392] Case 2: Ethernet-based business communication link;

[0393] Case 3: Business communication link based on any in-vehicle signal bus; or

[0394] Case 4: Ethernet-based service communication link and any in-vehicle signal bus-based service communication link.

[0395] When ECU1 is connected to the UDS installer through the distributed gateway, the UDS installer sends the first instruction information to ECU1 specifically: the UDS installer sends the first instruction information to ECU1 through the distributed gateway.

[0396] For the above scenario 4, the second communication link includes two communication links: an Ethernet-based service communication link and a service communication link based on any in-vehicle signal bus. In one implementation, the UDS installer sends the first instruction information to the distributed gateway via the Ethernet-based service communication link, and the distributed gateway then sends the first instruction information to ECU1 via the service communication link based on any in-vehicle signal bus. In another implementation, the UDS installer sends the first instruction information to the distributed gateway via the service communication link based on any in-vehicle signal bus, and the distributed gateway then sends the first instruction information to ECU1 via the Ethernet-based service communication link.

[0397] For the above situation 2, the process of sending the first indication information is, for example: the UDS installer sends the first indication information to the distributed gateway through the Ethernet-based service communication link, and the distributed gateway also sends the first indication information to ECU1 through the Ethernet-based service communication link.

[0398] For the above situation 1, the in-vehicle signal bus may be, for example, a CAN bus, a LIN bus, a FlexRay bus, etc. For example, a diagnostic communication link based on a CAN bus may be referred to as a DOCAN link, and a diagnostic communication link based on a LIN bus may be referred to as a DOLIN link.

[0399] In some possible embodiments, the first communication link may not be a DOIP link. In this case, other possible forms of the first communication link and the corresponding second communication link can refer to the relevant descriptions in Table 1 in the embodiment of Figure 2, and will not be repeated here.

[0400] S403: Within at least one detection cycle, the UDS installer repeatedly sends the first message to the ECU 1 based on the DOIP link. For details of this step, please refer to the description of the sending method of the first message in S302 in the embodiment of Figure 3, which will not be repeated here.

[0401] For example, in Figure 4, assuming that the duration of each detection cycle is T1, after the UDS installer sends the first indication information to ECU1 for the first time, the UDS installer does not receive a response from ECU1 to the first message (for example, the second message) on the DOIP link within T1, then the UDS installer sends the first indication information to ECU1 for the second time. If the UDS installer does not receive a response from ECU1 to the first message on the DOIP link within T1, then the UDS installer sends the first indication information to ECU1 for the third time, ..., until the UDS installer receives a response from ECU1 to the first message (for example, the second message) on the DOIP link within T1 after a certain sending of the first indication information, or the number of times the UDS installer sends the first indication information (or the number of times ECU1 performs the second reset operation) reaches the first threshold, the UDS installer stops sending the first indication information and also stops sending the first message to ECU1.

[0402] That is, during the process of sending the first instruction information and the first message, if the UDS installer receives feedback from ECU1 on the DOIP link regarding the first message, the UDS installer may stop sending the first instruction information and the first message.

[0403] S404: Within the target preset time period, ECU1 sends a second message to the UDS installer based on the DOIP link.

[0404] Here, the target preset time duration corresponds to the at least one detection cycle, for example, the target preset time duration includes the at least one detection cycle. The target preset time duration is equivalent to the first time range in the embodiment of FIG.

[0405] In one implementation, ECU1 sends a second message to the UDS installer over the DOIP link, including: ECU1 receives a first message from the UDS installer over the DOIP link; and in response to the first message, ECU1 sends a second message to the UDS installer over the DOIP link, wherein the second message includes the version number of the first upgrade software. In other words, if ECU1 receives the first message, it indicates that communication between ECU1 and the UDS installer over the DOIP link has been restored, and ECU1 and the UDS installer can continue to communicate over the DOIP link.

[0406] Furthermore, the second message is a heartbeat message, and the second message can also be used to indicate that ECU1 is alive or online.

[0407] In another implementation, ECU1 sends a second message to the UDS installer based on the DOIP link, including: after ECU1 performs the second reset operation each time, ECU1 repeatedly sends the second message to the UDS installer based on the DOIP link, wherein the second message is a heartbeat message, and the second message also includes the version number of the first upgrade software.

[0408] S405: Within at least one detection cycle, if the ECU 1 and the UDS installer resume communication, the UDS installer receives a second message on the DOIP link.

[0409] Furthermore, the version number included in the second message matches the version number of the first upgrade software, and the UDS installer determines that the ECU1 upgrade is successful. In other words, based on the second message, the UDS installer can obtain the version number of the latest upgrade software installed on ECU1, thereby confirming that the ECU1 upgrade is successful. This improves the reliability of ECU upgrades and also helps improve the success rate and reliability of vehicle upgrades.

[0410] In some possible embodiments, if the UDS installer does not receive the second message on the DOIP link within at least one of the above-mentioned detection cycles, the UDS installer may send feedback information to the OTA manager so that the OTA manager can perform a whole vehicle detection to attempt to restore the communication between the UDS installer and ECU1 based on the first communication link. For details, please refer to the relevant description of the embodiment of Figure 5 below. The feedback information is used to indicate that ECU1 has lost contact with the UDS installer.

[0411] In some possible embodiments, ECU1 includes a first partition and a second partition, wherein the first partition is used to store the first upgrade software, and the second partition is used to store the second upgrade software, the second upgrade software being the software used by the ECU before the first upgrade software is flashed. If the number of times the first indication information is sent reaches a first threshold and communication between ECU1 and the UDS installer has not yet been restored, the UDS installer may also send a rollback message to ECU1, the rollback information being used to instruct ECU1 to start the second upgrade software (or to instruct ECU1 to perform a rollback operation), wherein the rollback information is carried by a third communication link, which is different from the first communication link. Here, the third communication link can refer to the relevant description of the second communication link in S402 above, and will not be repeated here. It can be seen that the redundant communication link carries the rollback information, which can ensure that ECU1 can receive the rollback information, so that ECU1 can try to restore communication between ECU1 and the UDS installer by starting the old version of the software.

[0412] For example, the embodiment of the present application does not limit the number of times the UDS installer sends rollback information.

[0413] It is understandable that every time the OTA installer sends a rollback message, a detection cycle will be started.

[0414] Accordingly, after the UDS installer sends the rollback message to ECU1, if communication between ECU1 and the UDS installer is restored, the UDS installer receives a third message from ECU1 over the DOIP link in response to the first message. This third message includes the version number of the second upgrade software. Because the version number included in the third message is different from the version number of the first upgrade software, the UDS installer can determine that the ECU1 upgrade failed based on the third message. This means that the UDS installer can accurately determine the upgrade result of ECU1, facilitating subsequent accurate decision-making and ensuring the consistency of software versions across the entire vehicle.

[0415] Furthermore, when the UDS installer determines that the ECU1 upgrade has failed based on the received third message, the UDS installer can also send upgrade indication information to ECU1 based on the DOIP link. The upgrade indication information is used to instruct ECU1 to re-execute the OTA upgrade based on the first upgrade software, which is conducive to improving the success rate of the ECU upgrade.

[0416] For example, when the UDS installer sends a first indication message and a rollback message to ECU1, if the number of times the first indication message is sent reaches a first threshold and the number of times the rollback message is sent reaches a second threshold, and communication between ECU1 and the UDS installer has not yet been restored, that is, the UDS installer has not received the third message on the DOIP link, the UDS installer may also send feedback information to the OTA manager so that the OTA manager performs a vehicle inspection to try to restore communication between the UDS installer and ECU1. For details, please refer to the relevant description of the embodiment of Figure 5 below. The feedback information is used to indicate that ECU1 has lost contact with the UDS installer.

[0417] In some possible embodiments, when ECU1 has a partition for storing old version software, for example, the second partition of ECU1 is used to store the above-mentioned second upgrade software, the UDS installer in the above-mentioned S401 may not enable the sending of the first indication information, that is, not execute S402, but enable the sending of the rollback information to instruct ECU1 to start the second upgrade software, in order to try to solve the problem of loss of connection between ECU1 and the UDS installer, which is conducive to improving the success rate of restoring communication between ECU1 and the UDS installer.

[0418] It can be seen that, by implementing the embodiments of the present application, the UDS installer can send additional reset instruction information, such as the first instruction information, to the ECU via a redundant communication link other than the first communication link, such as the second communication link, to instruct the ECU to perform a second reset operation, thereby improving the success rate of restoring communication between the ECU and the UDS installer. In addition, if the ECU has a partition storing an old version of software, such as the second partition of the ECU is used to store the second upgraded software, if communication between the ECU and the UDS installer is still not restored after the reset instruction information is sent multiple times, the UDS installer can also send a rollback message to the ECU via the redundant communication link. Alternatively, the UDS installer can directly send a rollback message instead of a reset instruction message to attempt to resolve the ECU's loss of connection by starting the old version of software. In this way, the ECU rolls back to the old version of software before the upgrade, and the UDS installer can accurately know the upgrade result of the ECU, which is conducive to improving the reliability of the vehicle upgrade.

[0419] In some possible embodiments, when the OTA manager is aware that the ECU and the UDS installer have lost contact, or the problem of the loss of connection between the ECU and the UDS installer is still not resolved after executing the method shown in Figure 3 or Figure 4 above, the OTA manager can also try to solve the problem of the loss of connection between the ECU and the UDS installer from the perspective of vehicle inspection.

[0420] See FIG5 , which is a flowchart of another upgrade detection method provided in an embodiment of the present application.

[0421] This method can be applied to an upgrade detection system, which includes at least the aforementioned OTA installer, OTA manager, ECU, and vehicle power management module. The vehicle power management module, OTA installer, OTA manager, and ECU are deployed on the same vehicle. Here, the OTA installer is used as an example to illustrate the solution, but the OTA installer is not limited to being a UDS installer. The method includes but is not limited to the following steps:

[0422] S501: The UDS installer sends first reset information to the ECU based on the first communication link.

[0423] During the ECU upgrade process, the interactive information between the UDS installer and the ECU (e.g., the first reset message, the first message, and the response to the first message) is carried by the first communication link. For details about the first communication link, please refer to the description of the first communication link in the embodiment of FIG. 2 , and will not be repeated here.

[0424] Accordingly, the ECU receives the first reset information and performs a first reset operation based on the first reset information to start the first upgrade software, where the first upgrade software is the latest version of the upgrade software flashed to the ECU.

[0425] S502: The UDS installer repeatedly sends a first message to the ECU based on the first communication link.

[0426] Here, the first message is used to request to obtain the version number of the upgrade software currently used by the ECU.

[0427] Exemplarily, the first message may be sent by the UDS installer after receiving the ECU's response information to the first reset information on the first communication link, or may be sent by the UDS installer after receiving the result query information sent by the OTA manager, where the result query information is used to request the upgrade result of the ECU.

[0428] S503: During the detection period, if the UDS installer does not receive a response from the ECU to the first message on the first communication link, the UDS installer determines that the ECU and the UDS installer are disconnected.

[0429] The above steps S501-S503 can also refer to the relevant description of S401 in the embodiment of Figure 4 above, and will not be repeated here.

[0430] S504: When it is determined that the ECU loses contact with the UDS installer, the UDS installer sends feedback information to the OTA manager.

[0431] Correspondingly, the OTA manager receives feedback information sent by the UDS installer, wherein the feedback information is used to indicate that the ECU has lost contact with the UDS installer.

[0432] In some possible embodiments, the embodiment of Figure 5 may also be executed after the embodiment of Figure 3 or Figure 4 above. Specifically, S501-S503 in Figure 5 may not be executed. The triggering conditions for the UDS installer to send feedback information to the OTA manager can also refer to the relevant description of the UDS installer sending feedback information to the OTA manager in the embodiment of Figure 3 above, or refer to the relevant description of the UDS installer sending feedback information to the OTA manager in the embodiment of Figure 4 above, which will not be repeated here.

[0433] S505: The OTA manager controls the vehicle power management module to perform power-off and power-on operations in sequence.

[0434] Specifically, in response to the feedback information, the OTA manager sends a power-off instruction message to the vehicle power management module, which instructs the vehicle power management module to perform a power-off operation. Here, vehicle power-off includes ECU power-off and sleep, OTA manager power-off, and UDS installer power-off.

[0435] Furthermore, the OTA manager can also set a wake-up timer when sending the power-off indication message. If the wake-up timer reaches a preset value, the OTA manager restarts the process by sending a power-on indication message to the vehicle power management module. The power-on indication message is used to instruct the vehicle power management module to perform a power-on operation. The power-off indication message and the power-on indication message are used by the ECU to perform a second reset operation. The second reset operation can be specifically described in the embodiment of FIG2 , and will not be repeated here.

[0436] In other words, by controlling the power-on and power-off of the entire vehicle, the ECU can indirectly perform a second reset operation. This helps solve the problem of loss of connection between the ECU and the UDS installer. The OTA manager can also retry the version number verification of the lost ECU before the vehicle is powered off.

[0437] S506: The OTA manager sends a result query message to the UDS installer. The result query message is used to request the upgrade result of the ECU.

[0438] S507: The UDS installer repeatedly sends the first message to the ECU based on the first communication link.

[0439] S508: During the detection period, if the UDS installer receives a response from the ECU to the first message on the first communication link, the UDS installer sends result information to the OTA manager, where the result information is used to indicate the upgrade result of the ECU.

[0440] Here, the result information is obtained by the UDS installer based on the response of the ECU to the first message.

[0441] In one implementation, when the ECU responds to the first message with the second message mentioned above, and the second message includes the version number of the first upgrade software, the UDS installer determines that the ECU upgrade is successful based on the second message. In this case, the result information is used to indicate that the ECU upgrade is successful.

[0442] In one implementation, the ECU's response to the first message is the third message in the embodiment of Figure 3 or Figure 4 above. The third message includes the version number of the second upgrade software. The second upgrade software is the software used by the ECU to install the first upgrade software. Since the version number carried by the second message is different from the version number of the first upgrade software, the UDS installer determines that the ECU upgrade has failed. In this case, the result information is used to indicate that the ECU upgrade has failed.

[0443] Here, when the ECU's response to the first message is the above-mentioned third message, it means that the ECU also performs a rollback operation after performing the second reset operation. For example, in the embodiment of Figure 3, the ECU performs a rollback operation, or, in the embodiment of Figure 4, the ECU performs a rollback operation based on the rollback information sent by the UDS installer.

[0444] S509: Within the target time range, the OTA manager receives the result information sent by the UDS installer and obtains the upgrade result of the ECU according to the result information.

[0445] Exemplarily, the target time range may be represented by two absolute times, or by a starting time and a duration. The starting time of the target time range may be, for example, the time when the result query information is sent in S506.

[0446] Here, the OTA manager can know the upgrade results of the ECU based on the result information. According to this method, the OTA manager can accurately know the upgrade results of each ECU in the vehicle. When unifying the software version used in the entire vehicle, the OTA manager can accurately decide whether a certain ECU should be upgraded or rolled back. For example, during a vehicle upgrade, ECU1 was successfully upgraded and ECU2 failed to upgrade (that is, the rollback was successful). In this case, in order to ensure the uniformity of the software version, ECU2 can be instructed to upgrade again or ECU1 can be instructed to roll back. In this way, the business can be realized to run normally in a working environment with matching software versions.

[0447] In some possible embodiments, if the result information indicates that the ECU upgrade has failed, it also indirectly reflects that the communication between the ECU and the UDS installer based on the first communication link has been restored. The OTA manager can also send upgrade indication information to the ECU through the UDS installer based on the first communication link. The upgrade indication information is used to instruct the ECU to re-execute the OTA upgrade based on the first upgrade software.

[0448] In some possible embodiments, if the OTA installer does not receive the above result information within the target time range, the OTA manager may also prompt the vehicle user that the ECU has lost contact with the UDS installer and request manual processing.

[0449] Here, the user of the vehicle may be, for example, a driver, an owner of the vehicle, or a person who can use the vehicle.

[0450] For example, the OTA installer may control the display of a prompt message, which is used to inform the vehicle user that "the ECU has lost contact with the UDS installer, requesting manual processing."

[0451] The prompt information can be presented on a vehicle tablet, an onboard display, or a head-up display (HUD) system, or on a display of a user terminal. The display can be, for example, a liquid crystal display (LCD), an organic or inorganic light-emitting diode (OLED), an active matrix / organic light-emitting diode (AMOLED), etc.

[0452] It can be seen that after the implementation of this application, when the UDS installer senses that the ECU has lost connection, it can also provide feedback to the OTA manager. The OTA manager will notify the entire vehicle to power off and sleep for a period of time and then power on again. In this way, the ECU can retry to start or run the new version of the upgrade software, which is conducive to improving the success rate of restoring communication between the ECU and the UDS installer, and can also be beneficial to the reliability of the vehicle upgrade.

[0453] 6 is a schematic diagram of the structure of an upgrade detection device provided in an embodiment of the present application. The upgrade detection device 30 includes a receiving unit 310, a processing unit 312, and a sending unit 314. The upgrade detection device 30 can be implemented by hardware, software, or a combination of hardware and software.

[0454] Here, the upgrade detection device 30 may be the above-mentioned ECU or be deployed in the ECU.

[0455] Among them, within the first time range, the receiving unit 310 receives a first message sent by the OTA installer, and in response to the first message, the sending unit 314 is used to send a second message to the OTA installer, the first message is used to request to obtain the version number of the upgrade software currently used by the ECU, and the second message is associated with the first message; wherein, before the first time range, the processing unit 312 performed a first reset operation and the ECU lost contact with the UDS installer, and the first reset operation was the first reset operation performed after the ECU flashed the first upgrade software; wherein, within the first time range, and before the receiving unit 310 received the first message, the processing unit 312 performed at least one second reset operation.

[0456] The upgrade detection device 30 can be used to implement the ECU-side method described in the embodiments of FIG. 2 or FIG. 5 , or the ECU 1-side method described in the embodiments of FIG. 3 or FIG. 4 . For example, in FIG. 2 , the receiving unit 310 and the processing unit 312 can be used to execute S201 and S203 , and the sending unit 314 can be used to execute S204 . For another example, in FIG. 3 , the receiving unit 310 and the processing unit 312 can be used to execute S301 and S303 , and the sending unit 314 can be used to execute S304 .

[0457] 7 is a schematic diagram of the structure of another upgrade detection device provided in an embodiment of the present application. The upgrade detection device 40 includes a sending unit 410 and a receiving unit 412. The upgrade detection device 40 can be implemented in hardware, software, or a combination of hardware and software.

[0458] Here, the upgrade detection device 40 may be the above-mentioned OTA installer or be deployed in the OTA installer.

[0459] Within a first time range, the sending unit 410 is configured to perform a first operation, the first operation being configured to restore communication between the OTA installer and the ECU, where the ECU is an electronic control unit connected to the OTA installer. Prior to the first time range, the sending unit 410 is configured to send a first reset message, and the receiving unit 412 does not receive a response from the ECU to the first message. The first reset message is configured to request the ECU to perform a first reset operation, the first reset operation being the first reset operation performed by the ECU after the first upgrade software is flashed. The first message is configured to request the version number of the upgrade software currently used by the ECU.

[0460] If the ECU and the OTA installer resume communication within the first time range, the receiving unit 412 receives a second message from the ECU in response to the first message.

[0461] The upgrade detection device 40 may be used to implement the OTA installer-side method described in the embodiment of Figure 2, or the UDS installer-side method described in the embodiments of Figures 3, 4, or 5. For example, in Figure 2, the sending unit 410 may be used to execute S202, and the receiving unit 412 may be used to execute S205.

[0462] For another example, in FIG3 , the sending unit 410 may be used to execute S302 , and the receiving unit 412 may be used to execute S305 .

[0463] For another example, in FIG4 , the sending unit 410 may be used to execute S402 and S403 , and the receiving unit 412 may be used to execute S401 and S405 .

[0464] 8 is a schematic diagram of the structure of another upgrade detection device provided in an embodiment of the present application. The upgrade detection device 50 includes a receiving unit 510 and a sending unit 512. The upgrade detection device 50 can be implemented in hardware, software, or a combination of hardware and software.

[0465] Here, the upgrade detection device 50 may be the above-mentioned OTA manager or be deployed in the OTA manager.

[0466] Among them, the receiving unit 510 receives feedback information sent by the OTA installer, and the feedback information is used to indicate that the ECU has lost contact with the OTA installer; the sending unit 512 is used to send power-off indication information, and the power-off indication information is used for the ECU to perform a second reset operation. The second reset operation is a reset operation after the ECU performs the first reset operation. The first reset operation is the first reset operation performed by the ECU after the first upgrade software is flashed.

[0467] The upgrade detection device 50 may be used to implement the OTA administrator-side method described in the embodiment of FIG5 . For example, in the embodiment of FIG5 , the receiving unit 510 may be used to execute S504 and S508 , and the sending unit 512 may be used to execute S505 and S506 . In some possible embodiments, the upgrade detection device 50 further includes a processing unit (not shown), and the sending unit may be used to execute S509 .

[0468] It should be understood that the division of the various units in the above devices (such as the upgrade detection device 30, the upgrade detection device 40, or the upgrade detection device 50) is only a division of logical functions. In actual implementation, they can be fully or partially integrated into a physical entity, or they can be physically separated. In addition, the units in the device can be implemented in the form of a processor calling software; for example, the device includes a processor, the processor is connected to a memory, and the memory stores instructions. The processor calls the instructions stored in the memory to implement any of the above methods or realize the functions of the various units of the device, wherein the processor is, for example, a general-purpose processor, such as a central processing unit (CPU) or a microprocessor, and the memory is a memory within the device or a memory outside the device. Alternatively, the units in the device can be implemented in the form of hardware circuits, and the functions of some or all of the units can be realized by designing the hardware circuits. The hardware circuit can be understood as one or more processors. For example, in one implementation, the hardware circuit is an application-specific integrated circuit (ASIC), which realizes the functions of some or all of the above units by designing the logical relationship of the components in the circuit. For another example, in another implementation, the hardware circuit can be implemented by a programmable logic device (PLD). Taking a field programmable gate array (FPGA) as an example, it can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by configuring the configuration file, thereby realizing the functions of some or all of the above units. All units of the above devices can be implemented in the form of software called by the processor, or in the form of hardware circuits, or in part by software called by the processor, and the rest by hardware circuits.

[0469] In an embodiment of the present application, a processor is a circuit with a signal processing capability. In one implementation, the processor can be a circuit with instruction reading and execution capability, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), or a digital signal processor (DSP). In another implementation, the processor can implement certain functions through the logical relationship of a hardware circuit. The logical relationship of the hardware circuit is fixed or reconfigurable, such as a hardware circuit implemented by a processor as an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In a reconfigurable hardware circuit, the processor loads a configuration document to implement the process of hardware circuit configuration, which can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units. In addition, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), etc.

[0470] It can be seen that each unit in the above device can be one or more processors (or processing circuits) configured to implement the above method, such as: CPU, GPU, NPU, TPU, DPU, microprocessor, DSP, ASIC, FPGA, or a combination of at least two of these processor forms.

[0471] In addition, the various units in the above devices can be fully or partially integrated together, or can be implemented independently. In one implementation, these units are integrated together and implemented in the form of a system-on-a-chip (SOC). The SOC may include at least one processor for implementing any of the above methods or implementing the functions of the various units of the device. The type of the at least one processor can be different, for example, including a CPU and FPGA, a CPU and an artificial intelligence processor, a CPU and a GPU, etc.

[0472] Referring to Figure 9 , Figure 9 is a schematic diagram of the structure of a communication device provided in an embodiment of the present application. As shown in Figure 9 , communication device 90 includes a processor 901, a communication interface 902, a memory 903, and a bus 904. Processor 901, memory 903, and communication interface 902 communicate with each other via bus 904. It should be understood that this application does not limit the number of processors and memories in communication device 90.

[0473] In one implementation, the communication device 90 is the aforementioned electronic control unit ECU or is included in the ECU.

[0474] In one implementation, the communication device 90 is the above-mentioned OTA installer or is included in the OTA installer. For example, the OTA installer may be the above-mentioned unified diagnostic service UDS installer.

[0475] In one implementation, the communication device 90 is the above-mentioned over-the-air OTA manager or is included in the OTA manager.

[0476] Bus 904 may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, among others. Buses may be categorized as address buses, data buses, control buses, and the like. For ease of illustration, FIG9 illustrates a single bus line, but this does not imply a single bus or type of bus. Bus 904 may include a path for transmitting information between various components of communication device 90 (e.g., memory 903, processor 901, and communication interface 902).

[0477] The processor 901 can refer to the relevant description of the processor in the above embodiment, which will not be repeated here.

[0478] Memory 903 is used to provide storage space for storing data such as the operating system and computer programs. Memory 903 can be one or a combination of random access memory (RAM), erasable programmable read-only memory (EPROM), read-only memory (ROM), or compact disc read-only memory (CD-ROM). Memory 903 can exist independently or be integrated into processor 901.

[0479] The communication interface 902 may be used to provide information input or output for the processor 901. Alternatively, the communication interface 902 may be used to receive data transmitted externally and / or transmit data externally. It may be a wired link interface such as an Ethernet cable, or a wireless link interface (such as Wi-Fi, Bluetooth, or general wireless transmission). Alternatively, the communication interface 902 may further include a transmitter (such as a radio frequency transmitter, antenna, etc.) or a receiver coupled to the interface.

[0480] The processor 901 in the communication device 90 is used to read the computer program stored in the memory 903 to execute the aforementioned method, such as the method described in Figure 2, Figure 3, Figure 4 or Figure 5.

[0481] In one possible design, the communication device 90 may be one or more modules in an execution entity of the ECU-side method shown in FIG. 2 , FIG. 3 , FIG. 4 , or FIG. 5 . The processor 901 may be configured to read one or more computer programs stored in a memory to perform the following operations:

[0482] Within the first time range, a first message sent by the OTA installer is received by the receiving unit 310, and in response to the first message, a second message is sent to the OTA installer through the sending unit 314, wherein the first message is used to request the version number of the upgrade software currently used by the ECU, and the second message is associated with the first message; wherein, before the first time range, the processing unit 312 performs a first reset operation and the ECU loses connection with the UDS installer, and the first reset operation is the first reset operation performed after the ECU flashes the first upgrade software; wherein, within the first time range and before the first message is received by the receiving unit 310, the processing unit 312 performs at least one second reset operation.

[0483] In one possible design, the communication device 90 may be one or more modules in an execution entity that executes the UDS installer-side method shown in FIG. 2 , FIG. 3 , FIG. 4 , or FIG. 5 . The processor 901 may be configured to read one or more computer programs stored in a memory to perform the following operations:

[0484] Within a first time range, a first operation is performed by sending unit 410, the first operation being used to restore communication between the OTA installer and the ECU, where the ECU is an electronic control unit connected to the OTA installer. Prior to the first time range, sending unit 410 is used to send a first reset message, and receiving unit 412 does not receive a response from the ECU to the first message. The first reset message is used to request the ECU to perform a first reset operation, which is the first reset operation performed by the ECU after the first upgrade software is flashed. The first message is used to request the version number of the upgrade software currently used by the ECU.

[0485] Within the first time range, if the ECU and the OTA installer resume communication, a second message in response to the first message is received from the ECU via the receiving unit 412 .

[0486] In one possible design, the communication device 90 may be one or more modules in the execution body of the OTA administrator-side method shown in FIG5 . The processor 901 may be configured to read one or more computer programs stored in the memory to perform the following operations:

[0487] Feedback information sent by the OTA installer is received through the receiving unit 510, and the feedback information is used to indicate that the ECU has lost contact with the OTA installer; power-off indication information is sent through the sending unit 512, and the power-off indication information is used for the ECU to perform a second reset operation. The second reset operation is a reset operation after the ECU performs the first reset operation. The first reset operation is the first reset operation performed by the ECU after the first upgrade software is flashed.

[0488] In the embodiments described above, the descriptions of each embodiment have their own emphasis. For parts not described in detail in a particular embodiment, please refer to the relevant descriptions of other embodiments. In addition, in the various embodiments of this application, unless otherwise specified or there is a logical conflict, the terms and / or descriptions between the various embodiments are consistent and can be referenced to each other. The technical features in different embodiments can be combined to form new embodiments based on their inherent logical relationships.

[0489] It should be noted that, those skilled in the art can see that all or part of the steps in the various methods of the above embodiments can be completed by a program to instruct relevant hardware. The program can be stored in a computer-readable storage medium, and the storage medium includes a read-only memory (ROM), a random access memory (RAM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), a one-time programmable read-only memory (OTPROM), an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, magnetic disk storage, magnetic tape storage, or any other computer-readable medium that can be used to carry or store data.

[0490] The technical solution of the present application may essentially or contribute to the part or all or part of the technical solution in the form of a software product. The computer program product is stored in a storage medium and includes a number of instructions for enabling a device (which may be a personal computer, a server, or a network device, a robot, a single-chip microcomputer, a chip, a robot, etc.) to execute all or part of the steps of the method described in each embodiment of the present application.

Claims

1. An upgrade detection method, characterized in that: The method comprises: Within a first time range, an electronic control unit ECU receives a first message sent by an over-the-air OTA installer, and in response to the first message, the ECU sends a second message to the OTA installer, wherein the first message is used to request to obtain a version number of an upgrade software currently used by the ECU; Before the first time range, the ECU performs a first reset operation and the ECU loses contact with the OTA installer, and the first reset operation is the first reset operation performed by the ECU after the first upgrade software is flashed; Wherein, within the first time range and before the ECU receives the first message, the ECU performs at least one second reset operation.

2. The method according to claim 1, characterized in that The first message and the second message are carried by a first communication link, and the first communication link includes a diagnostic communication link based on Ethernet and / or a diagnostic communication link based on a first in-vehicle signal bus.

3. The method according to claim 2, characterized in that The second message includes the version number of the first upgrade software.

4. The method according to claim 2 or 3, characterized in that: The triggering condition for the ECU to perform the at least one second reset operation is: The ECU does not receive the first message sent by the OTA installer within a first preset time after the ECU starts the first upgrade software; Within a second preset time period after the ECU starts the first upgrade software, the ECU does not receive a heartbeat message sent by the OTA installer; The ECU receives first indication information, where the first indication information is used to indicate that the ECU is disconnected from the OTA installer, or is used to indicate that the ECU starts to perform the second reset operation; or, The ECU receives power-off indication information, and the power-off indication information is used by the ECU to perform the second reset operation.

5. The method according to claim 4, characterized in that The first indication information is carried through a second communication link, and the second communication link is different from the first communication link.

6. The method according to claim 4 or 5, characterized in that: The number of times the second reset operation is performed is associated with the number of times the ECU receives the first indication information.

7. The method according to any one of claims 2 to 5, characterized in that: The first time range is at least one first detection cycle, and the at least one second reset operation corresponds to the at least one first detection cycle.

8. The method according to any one of claims 2 to 7, characterized in that: The method further comprises: When the number of the at least one second reset operation reaches a first threshold, the ECU stops monitoring the first message on the first communication link.

9. The method according to any one of claims 2 to 7, characterized in that: The ECU includes a first partition and a second partition, the first partition is used to store the first upgrade software, the second partition is used to store the second upgrade software, the second upgrade software is the software used by the ECU before the first upgrade software is flashed, the number of the at least one second reset operation reaches a first threshold, and the method further includes: The ECU starts the second upgrade software; In the second detection cycle, if the ECU receives the first detection signal from the OTA installer based on the first communication link, a message, sending a third message to the OTA installer based on the first communication link; The third message includes the version number of the second upgrade software.

10. The method according to claim 9, characterized in that Before the ECU starts the second upgrade software, the method further includes: The ECU receives rollback information sent by the OTA installer, where the rollback information is carried by a second communication link, where the second communication link is different from the first communication link; The ECU starts the second upgrade software, including: the ECU starts the second upgrade software based on the rollback information.

11. The method according to any one of claims 5 to 10, characterized in that: The ECU is communicatively connected with the OTA installer through a distributed gateway in the vehicle, the first communication link includes a diagnostic communication link based on Ethernet and a diagnostic communication link based on a first in-vehicle signal bus, and the second communication link includes: At least one of a service communication link based on a second in-vehicle signal bus and a service communication link based on Ethernet; or a third communication link and a fourth communication link, the third communication link being used to connect the OTA installer with the distributed gateway, and the fourth communication link being used to connect the distributed gateway with the ECU; Wherein, if the Ethernet-based diagnostic communication link in the first communication link is used to connect the OTA installer with the distributed gateway and the diagnostic communication link based on the first in-vehicle signal bus in the first communication link is used to connect the distributed gateway with the ECU, When the third communication link is a diagnostic communication link based on any in-vehicle signal bus, the fourth communication link is a diagnostic communication link based on Ethernet or a diagnostic communication link based on a third in-vehicle signal bus, and the third in-vehicle signal bus is different from the first in-vehicle signal bus; or When the third communication link is a service communication link based on Ethernet or any in-vehicle signal bus, the fourth communication link is a service communication link based on Ethernet or any in-vehicle signal bus.

12. An upgrade detection method, characterized in that: The method comprises: Within a first time range, the over-the-air OTA installer performs a first operation, the first operation being used to restore communication between the OTA installer and an electronic control unit ECU, the ECU being an electronic control unit connected to the OTA installer; wherein, before the first time range, the OTA installer sends a first reset message and does not receive a response to a first message from the ECU, the first reset message being used to request the ECU to perform a first reset operation, the first reset operation being the first reset operation performed by the ECU after the first upgrade software is flashed, and the first message being used to request to obtain a version number of the upgrade software currently used by the ECU; If the ECU and the OTA installer resume communication within the first time range, the OTA installer receives a second message from the ECU in response to the first message.

13. The method according to claim 12, characterized in that The first operation includes: repeatedly sending the first message.

14. The method according to claim 13, characterized in that The first message and the second message are carried by a first communication link, and the first communication link includes a diagnostic communication link based on Ethernet and / or a diagnostic communication link based on a first in-vehicle signal bus.

15. The method according to claim 13 or 14, characterized in that The ECU includes a first partition and a second partition, the first partition is used to store the first upgrade software, the second partition is used to store the second upgrade software, the second upgrade software is the software used by the ECU before the first upgrade software is flashed, and the first operation further includes: Rollback information is sent at least once based on a second communication link, where the rollback information is used to instruct the ECU to start the second upgrade software, and the second communication link is different from the first communication link.

16. The method according to claim 13 or 14, characterized in that The first operation further includes: sending first indication information at least once based on a second communication link, the first indication information being used to indicate that the ECU is disconnected from the OTA installer or to indicate that the ECU performs a second reset operation, the second communication link being different from the first communication link; or A heartbeat message is sent based on the first communication link.

17. The method according to claim 16, characterized in that The number of times the second reset operation is performed is associated with the number of times the first indication information is sent.

18. The method according to claim 16 or 17, characterized in that The ECU includes a first partition and a second partition, the first partition is used to store the first upgrade software, the second partition is used to store the second upgrade software, the second upgrade software is the software used by the ECU before the first upgrade software is flashed, and the first operation further includes: When the number of times the first indication information is sent reaches a first threshold and communication between the ECU and the OTA installer has not been restored, the OTA installer sends rollback information to the ECU based on a second communication link, and the rollback information is used to instruct the ECU to start the second upgrade software. The second communication link is different from the first communication link.

19. The method according to any one of claims 12 to 18, characterized in that: After the OTA installer receives the second message, the method further includes: The version number included in the second message is the same as the version number of the first upgrade software, and the OTA installer determines that the ECU upgrade is successful; or, The version number included in the second message is different from the version number of the first upgrade software, and the OTA installer determines that the ECU upgrade has failed.

20. The method according to claim 19, characterized in that After determining that the ECU upgrade fails, the method further includes: Sending upgrade indication information to the ECU, wherein the upgrade indication information is used to instruct the ECU to re-execute the OTA upgrade based on the first upgrade software.

21. The method according to any one of claims 12 to 20, characterized in that: If the OTA installer does not receive the second message within the first time range, the method further includes: The OTA installer sends feedback information to the OTA manager, where the feedback information is used to indicate that the ECU is out of contact with the OTA installer.

22. The method according to any one of claims 15 to 21, characterized in that: The ECU is communicatively connected with the OTA installer through a distributed gateway in the vehicle, the first communication link includes a diagnostic communication link based on Ethernet and a diagnostic communication link based on a first in-vehicle signal bus, and the second communication link includes: At least one of a service communication link based on a second in-vehicle signal bus and a service communication link based on Ethernet; or a third communication link and a fourth communication link, the third communication link being used to connect the OTA installer with the distributed gateway, and the fourth communication link being used to connect the distributed gateway with the ECU; Wherein, if the Ethernet-based diagnostic communication link in the first communication link is used to connect the OTA installer with the distributed gateway and the diagnostic communication link based on the first in-vehicle signal bus in the first communication link is used to connect the distributed gateway with the ECU, When the third communication link is a diagnostic communication link based on any in-vehicle signal bus, the fourth communication link is based on A diagnostic communication link based on Ethernet or a diagnostic communication link based on a third in-vehicle signal bus, the third in-vehicle signal bus being different from the first in-vehicle signal bus; or When the third communication link is a service communication link based on Ethernet or any in-vehicle signal bus, the fourth communication link is a service communication link based on Ethernet or any in-vehicle signal bus.

23. An upgrade detection method, characterized in that: The method comprises: The over-the-air OTA manager receives feedback information sent by the OTA installer, where the feedback information is used to indicate that the electronic control unit ECU is out of contact with the OTA installer; The OTA manager sends a power-off indication message, and the power-off indication message is used for the ECU to perform a second reset operation. The second reset operation is a reset operation after the ECU performs a first reset operation. The first reset operation is the first reset operation performed after the ECU flashes the first upgrade software.

24. The method according to claim 23, characterized in that After the OTA manager sends the power-off indication information, the method further includes: Within a preset time period, the OTA manager receives result information sent by the OTA installer, where the result information is used to indicate an upgrade result of the ECU, and the result information is a response to the result query information sent by the OTA manager; The OTA manager obtains the upgrade result of the ECU according to the result information.

25. The method according to claim 24, characterized in that The method further comprises: If the OTA manager does not receive the result information within the preset time period, the OTA manager prompts the vehicle user that the ECU has lost contact with the OTA installer and requests manual processing.

26. An upgrade detection device, characterized in that: The device is an electronic control unit ECU or is included in the ECU, and the device includes a receiving unit, a processing unit and a sending unit, wherein: The receiving unit receives a first message sent by an over-the-air OTA installer within a first time range, and in response to the first message, the sending unit is used to send a second message to the OTA installer, wherein the first message is used to request to obtain a version number of the upgrade software currently used by the ECU; Before the first time range, the processing unit performs a first reset operation and the ECU loses contact with the OTA installer, and the first reset operation is the first reset operation performed by the processing unit after the first upgrade software is flashed; Wherein, within the first time range and before the receiving unit receives the first message, the processing unit performs at least one second reset operation.

27. An upgrade detection device, characterized in that: The device is an over-the-air OTA installer or is included in the OTA installer, and the device includes: a sending unit and a receiving unit, wherein: Within a first time range, the sending unit is used to perform a first operation, the first operation is used to restore communication between the OTA installer and an electronic control unit ECU, the ECU being an electronic control unit connected to the OTA installer; wherein, before the first time range, the sending unit sends a first reset message and the receiving unit does not receive a response from the ECU to a first message, the first reset message is used to request the ECU to perform a first reset operation, the first reset operation is the first reset operation performed by the ECU after the first upgrade software is flashed, and the first message is used to request to obtain a version number of the upgrade software currently used by the ECU; If the ECU resumes communication with the OTA installer within the first time range, the receiving unit receives a second message from the ECU in response to the first message.

28. An upgrade detection device, characterized in that: The device is an over-the-air OTA manager or is included in the OTA manager, and the device includes: a receiving unit and a sending unit, wherein: The receiving unit receives feedback information sent by the OTA installer, where the feedback information is used to indicate that the electronic control unit ECU is out of contact with the OTA installer; The sending unit is used to send power-off indication information, and the power-off indication information is used for the ECU to perform a second reset operation. The second reset operation is a reset operation after the ECU performs a first reset operation. The first reset operation is the first reset operation performed after the ECU flashes the first upgrade software.

29. An electronic control unit, characterized in that: The electronic control unit is used to implement the method described in any one of claims 1-11.

30. A chip, characterized in that: The chip includes at least one processor and a communication interface; The communication interface is used to receive and / or send data, and / or the communication interface is used to provide input and / or output for the processor; The at least one processor is used to implement the method of any one of claims 1-11, or to implement the method of any one of claims 12-22, or to implement the method of any one of claims 23-25.

31. An upgrade detection system, characterized in that: The system includes a first device and a second device, or includes a first device, a second device and a third device, wherein the first device is used to implement the method as described in any one of claims 1-11, the second device is used to implement the method as described in any one of claims 12-22, and the third device is used to implement the method as described in any one of claims 23-25.

32. A vehicle, characterized in that: The vehicle comprises at least one of the apparatus of claim 26 or 29, the apparatus of claim 27, and the apparatus of claim 28, or comprises the upgrade detection system of claim 31.

33. A computer-readable storage medium, characterized in that The computer-readable storage medium stores program instructions, and the program instructions are used to implement the method according to any one of claims 1-11 or 12-22 or 23-25.

34. A computer program product, characterized in that The method comprises computer instructions, which, when executed on a processor, implement the method as claimed in any one of claims 1-11, 12-22 or 23-25.